logo

Underground Malicious Tools: Investigating Propagation

ID: 569a2fdd-5ea8-59ce-9993-d79ec3bb0e5e

STIX ID: report--569a2fdd-5ea8-59ce-9993-d79ec3bb0e5e

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-29

Date Updated: 2026-07-20

...
...

This report documents underground forum activity promoting several criminal offerings: the Trigona ransomware affiliate program (RaaS) with double extortion and ancillary services (DDoS, Tor admin panel, leaked DB storage), the Meduza stealer (C++ build targeting browsers, wallets, and credentials), ShadowVault macOS stealer (PKG/DMG delivery, keychain extraction, wide wallet/browser support, and optional forged Apple signatures), and the evolving LummaC2 stealer (Windows-targeting MaaS with load-balancing and build-generation modules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.