CapCut Users Under Fire
ID: a157f426-a7a3-550d-927a-b9fac986113c
STIX ID: report--a157f426-a7a3-550d-927a-b9fac986113c
Feed Name: Cyble Blog
Phishing websites pretending to be CapCut installers are actively distributing multiple info-stealers and loaders: CRIL analysts detail an Offx stealer (Python/PyInstaller) that harvests browser credentials, cookies, screenshots, targeted app data, and desktop files, exfiltrates via Telegram or AnonFiles, and deletes traces; a separate BATLoader campaign drops RedLine and an AMSI-bypass .NET payload. The report provides technical analysis, targeted application/file paths, IOCs (hashes and domains), MITRE mappings, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
