logo

InnfiRAT is aiming for cryptocurrency

ID: 773452fd-4a80-5ad1-9d4c-099b7be14d78

STIX ID: report--773452fd-4a80-5ad1-9d4c-099b7be14d78

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed InnfiRAT, a .NET remote-access trojan that establishes a duplex WCF channel to a C2 (tcp://62.210.142.219:17231/IVictim), performs anti-VM checks, persists via scheduled tasks, exfiltrates browser cookies, cryptocurrency wallets and desktop text files, captures screenshots, kills browser/process monitoring tools, and can download and execute additional payloads; the report includes an MD5, a download URL, and the C2 address as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.