Underground Malicious Tools: Investigating Propagation
ID: 569a2fdd-5ea8-59ce-9993-d79ec3bb0e5e
STIX ID: report--569a2fdd-5ea8-59ce-9993-d79ec3bb0e5e
Feed Name: Cyble Blog
This report documents underground forum activity promoting several criminal offerings: the Trigona ransomware affiliate program (RaaS) with double extortion and ancillary services (DDoS, Tor admin panel, leaked DB storage), the Meduza stealer (C++ build targeting browsers, wallets, and credentials), ShadowVault macOS stealer (PKG/DMG delivery, keychain extraction, wide wallet/browser support, and optional forged Apple signatures), and the evolving LummaC2 stealer (Windows-targeting MaaS with load-balancing and build-generation modules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
