From fake Proton VPN sites to gaming mods, this Windows infostealer is everywhere
ID: b232e24d-7d0e-5349-8d92-ffb8cff4a90c
STIX ID: report--b232e24d-7d0e-5349-8d92-ffb8cff4a90c
Feed Name: Malwarebytes Blog
This report describes multiple active campaigns distributing NWHStealer, an infostealer that harvests browser data, saved passwords, and cryptocurrency wallet files. Attackers distribute malicious archives via fake VPN websites, code- and file-hosting platforms, compromised YouTube links, and free web hosting (onworks.net), using loaders such as MSI/Node.js, DLL hijacking, process hollowing (RegAsm), in-memory execution, and a CMSTP UAC bypass; the report includes hashes, domains, URLs, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
