New Cheana Stealer Threat Targets VPN Users Across Multiple Operating Systems
ID: 7a1fd189-e003-5237-af9e-0a579f2fd5e9
STIX ID: report--7a1fd189-e003-5237-af9e-0a579f2fd5e9
Feed Name: The Cyber Express
The Cheana Stealer campaign uses a phishing site impersonating a VPN service (WarpVPN) and an associated Telegram channel to distribute OS-specific installers that deploy malicious components (PowerShell scripts and malicious Python packages on Windows, shell scripts on Linux and macOS). These implants harvest browser passwords, cryptocurrency extension and wallet data, SSH keys and macOS Keychain items, archive them, and exfiltrate to a command-and-control server over HTTPS. The report details the technical delivery methods, the role of the Telegram channel in distribution, and recommends mitigations including obtaining software from trusted sources, endpoint protections, network monitoring, MFA and updated incident response plans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
