logo

MetaStealer Malware Targets US Asylum Seekers

ID: d46969ad-5a6f-569e-a666-7a0f2c2cd9aa

STIX ID: report--d46969ad-5a6f-569e-a666-7a0f2c2cd9aa

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

Cyble Research and Intelligence Labs discovered a ZIP-based campaign distributing MetaStealer: a shortcut LNK masquerading as a PDF extracts and runs a bundled VPN executable that sideloads a malicious libcrypto DLL, which drops an MSI that unpacks a CAB containing MetaStealer. The installer also launches a legitimate-looking I-589 PDF to deceive victims while the stealer collects browser credentials and system data and communicates with C2 domains (ykqmwgsuummieaug.xyz, kiyaqoimsiieeyqa.xyz) over HTTP(S); the report provides IOCs, MITRE mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.