Bandit Stealer
ID: 8c62da2a-480b-518a-8da8-ab7ef48e47d7
STIX ID: report--8c62da2a-480b-518a-8da8-ab7ef48e47d7
Feed Name: Zscaler Security Research Blog
Bandit Stealer is an information-stealer that employs extensive anti-VM and anti-debugging checks to evade analysis and targets a wide range of browsers, desktop and extension cryptocurrency wallets, FTP and email clients, and system artifacts to exfiltrate credentials, cookies, payment data, keystrokes and clipboard contents. Stolen data is aggregated into files under %appdata%\local (country_code + IP folder) and the malware uses Windows APIs and utilities (CryptUnprotectData, GetAdaptersAddresses, WMIC, CreateToolhelp32Snapshot) to collect system identifiers and avoid sandboxed environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
