Mercurial Grabber Malware Builder
ID: 5c79a789-778b-5ff5-aaa0-a7940eab8365
STIX ID: report--5c79a789-778b-5ff5-aaa0-a7940eab8365
Feed Name: Cyble Blog
Mercurial Grabber is an open-source C# stealer builder that has been repurposed by threat actors to harvest browser credentials and cookies (Chrome, Roblox, Minecraft), Windows product keys, Discord tokens, system and geolocation details, and screenshots. The analysis documents its persistence, anti-VM/anti-debug checks, embedded SQLite and AES-GCM encryption, configurable C2 communications, MITRE ATT&CK mappings, IoCs (SHA-1/SHA-256 hashes), and recommends standard defensive measures (MFA, updates, antivirus, cautious handling of pirated software and phishing).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
