Statc Stealer
ID: e4fade0f-4822-5c3d-abad-1bdbbadddd23
STIX ID: report--e4fade0f-4822-5c3d-abad-1bdbbadddd23
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of Statc Stealer, an information-stealing Windows binary that performs anti-analysis filename checks, collects browser credentials and autofill data from major browsers, harvests many cryptocurrency wallet types, encrypts the data into Temp text files, and exfiltrates it to a remote C2 using PowerShell Invoke-WebRequest. The analysis includes decrypted strings, ProcMon evidence, targeted browser/wallet lists, and an example exfiltration command and URL to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
