logo

New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

ID: 687cdc5e-4560-52d1-b6ae-a7b2601cea2b

STIX ID: report--687cdc5e-4560-52d1-b6ae-a7b2601cea2b

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-20

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**Fickle Stealer**, a new Rust-based information stealer, is being delivered via VBA droppers/downloaders, link and executable downloaders and PowerShell scripts that attempt UAC bypass; it performs anti-analysis checks, harvests browser data, crypto wallets, messaging and remote-access applications, collects targeted document and wallet files, and exfiltrates data (JSON) to attacker-controlled servers and a Telegram bot. The report also notes AZStealer, an open-source Python stealer advertised for Discord, which exfiltrates via Discord webhooks or Gofile and targets documents and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.