Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time
ID: fc026219-21ab-5f29-80f3-225db654e165
STIX ID: report--fc026219-21ab-5f29-80f3-225db654e165
Feed Name: ANY.RUN's Cybersecurity Blog
Threat Score
This report analyzes the agenteV2 campaign: a Brazilian-focused phishing operation delivering a VBS loader that installs a Nuitka-compiled stealer DLL which establishes a persistent WebSocket backdoor (uws://) to stream the victim's screen and provide an interactive remote shell for operator-assisted banking fraud; the analysis provides full infection-chain details, IOCs (domains, IPs, hashes, JA3), MITRE mapping, and remediation/detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
