Creal: New Stealer Targets Crypto Users Via Phishing
ID: 39b0a039-4594-50a1-bde1-24013645c601
STIX ID: report--39b0a039-4594-50a1-bde1-24013645c601
Feed Name: Cyble Blog
**Creal Stealer** is an open-source Python-based information stealer actively abused by threat actors to harvest browser cookies, credentials, crypto wallets, chat/gaming app data and extensions; it was distributed via phishing sites and hosted payloads (Dropbox) with at least ~50 observed samples, includes extensive environment-evasion checks, persistence via Startup folder, and exfiltration over Discord/web file hosts—IoCs (file hashes, URLs) and mitigation recommendations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
