New Information Stealer Targeting Crypto Wallets: Key Threats
ID: fe1e923b-df07-50e1-819f-2567a40beea5
STIX ID: report--fe1e923b-df07-50e1-819f-2567a40beea5
Feed Name: Cyble Blog
Doenerium Stealer: Cyble CRIL observed a spear-phishing campaign that lures Office365 users to a malicious domain hosting a trojanized “Microsoft Windows Malicious Software Removal Tool” executable (masquerading as Node.exe). The malware implements sandbox/VM checks, kills analysis/virtualization tools, establishes persistence, harvests browser data, Discord tokens and crypto wallet addresses (including clipboard clipping), compresses collected artifacts and exfiltrates via a Discord webhook; the report includes technical analysis and IOCs (hashes, URLs, domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
