LOLI Stealer: Golang InfoStealer Found In The Wild
ID: ddd68ff6-172e-5faa-bcda-434314bc8773
STIX ID: report--ddd68ff6-172e-5faa-bcda-434314bc8773
Feed Name: Cyble Blog
LOLI Stealer is a recently observed Golang-based info stealer offered via a malware-as-a-service (MaaS) model that harvests browser credentials, cookies, histories, crypto-wallet files (multiple wallet paths referenced), Telegram and Steam session data, desktop text files, and screenshots; it packages stolen data into a ZIP, encodes it in Base64 with metadata, and posts it to a C2 at http://webStealer.ru/gate.php. Cyble's analysis examined a UPX-packed 64-bit Go binary (SHA256 provided), noted anti-analysis checks (WINE detection), enumerated targeted wallet and browser paths, captured the data exfiltration mechanism and panel screenshots, and published mitigations and IOCs including hashes and the C2 URL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
