Felipe, a new infostealer Trojan
ID: 6ca18c7a-d907-502d-ae4e-b8edaba8e96b
STIX ID: report--6ca18c7a-d907-502d-ae4e-b8edaba8e96b
Feed Name: Zscaler Security Research Blog
Threat Score
**Felipe infostealer (Windows)**: This report analyzes the Felipe infostealer which installs persistently on Windows (32/64-bit), disables Defender and UAC protections, scrapes process memory and keystrokes to harvest payment card and personal data (using Luhn-style validation), encrypts exfiltrated data with 3DES, and sends it to a remote C2; the analysis includes dropped file paths, persistence mechanisms, memory-dumping methods, sample hashes, and download URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
