logo

New Editbot Stealer Spreads Via Social Media Messages

ID: a175f67b-1108-56dd-94fa-5e6254a63dc5

STIX ID: report--a175f67b-1108-56dd-94fa-5e6254a63dc5

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-07-02

Date Updated: 2026-07-16

...
...

CRIL analyzed a multi-stage social-media-distributed campaign delivering a Python-based Windows stealer dubbed "editbot": a RAR attachment contains a BAT that uses PowerShell to download a persistent startup BAT and a ZIP from GitLab, which installs and runs libb1.py to harvest browser credentials, cookies, system/process information and bundle them for exfiltration to a Telegram bot; the report includes technical analysis, hashes, a YARA rule, MITRE ATT&CK mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.