logo

Infostealers Crash Course: A Tradecraft Tuesday Recap

ID: 71ef30e7-cb00-5aae-8b6a-1e7e9a0aba08

STIX ID: report--71ef30e7-cb00-5aae-8b6a-1e7e9a0aba08

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2025-06-03

Date Updated: 2026-04-28

...
...

This Huntress report reviews the evolution and current threat landscape of infostealer malware, detailing historic families (Zeus, RedLine), recent source-code leaks (Banshee) spawning macOS variants, major underground marketplaces, law enforcement takedowns (Genesis, Lumma, RedLine), and observed in-the-wild incidents (Lumma delivery disguised as Notion with artifacts like "raretemp"). It describes the types of data infostealers harvest (SSO/SSAML, Slack tokens, API keys, MFA/OTP, crypto wallets), distribution methods (phishing, malvertising, trojanized apps), common IOCs and TTPs, and recommended mitigations such as MFA, EDR, patching, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.