Dissecting Saintstealer
ID: bc6e0bcb-bb6b-53dd-81a1-30767293d96a
STIX ID: report--bc6e0bcb-bb6b-53dd-81a1-30767293d96a
Feed Name: Cyble Blog
**Executive summary:** This report analyzes Saintstealer, a C#.NET information stealer used since November 2021 that harvests browser credentials, cookies, autofill data, credit cards, VPN/Steam/Telegram artifacts and screenshots, employs anti-analysis and VM/sandbox detection, compresses stolen data into a password-protected ZIP, and exfiltrates results to a Telegram channel and a C2 (http://f0591243.xsph.ru / 141.8.197.42); the report provides technical details, targeted sites/browsers, MITRE mappings and IoCs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
