Mystic Stealer Revisited
ID: 703d66bb-22f3-574b-bf53-03f04dd4965f
STIX ID: report--703d66bb-22f3-574b-bf53-03f04dd4965f
Feed Name: Zscaler Security Research Blog
This report analyzes Mystic Stealer, a Windows information-stealing malware that uses Base64-encoded HTTP POST communications with a C2 to register infected hosts, receive binary-flag configuration, exfiltrate browser data (cookies, history, extensions), cryptocurrency wallet files, screenshots and arbitrary files, and to download additional executable payloads via a loader mechanism; the analysis includes C2 request/response formats, target lists, and notes on debug builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
