New Editbot Stealer Spreads Via Social Media Messages
ID: a175f67b-1108-56dd-94fa-5e6254a63dc5
STIX ID: report--a175f67b-1108-56dd-94fa-5e6254a63dc5
Feed Name: Cyble Blog
CRIL analyzed a multi-stage social-media-distributed campaign delivering a Python-based Windows stealer dubbed "editbot": a RAR attachment contains a BAT that uses PowerShell to download a persistent startup BAT and a ZIP from GitLab, which installs and runs libb1.py to harvest browser credentials, cookies, system/process information and bundle them for exfiltration to a Telegram bot; the report includes technical analysis, hashes, a YARA rule, MITRE ATT&CK mappings, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
