logo

CoralRaider Malware Campaign Exploits CDN Cache to Spread Info-Stealers

ID: 70f87ac7-c8da-5be3-bd93-58e2cefdd138

STIX ID: report--70f87ac7-c8da-5be3-bd93-58e2cefdd138

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-24

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos observed an ongoing global malware campaign (since at least Feb 2024) distributing three stealers—CryptBot, LummaC2, and Rhadamanthys—hosted on CDN cache domains and attributed with moderate confidence to the actor CoralRaider; the attack chain uses phishing links to ZIPs containing Windows shortcut (LNK) files that execute PowerShell to fetch an HTA which launches an embedded PowerShell loader employing the FoDHelper UAC bypass, ultimately installing stealers that harvest system/browser data, credentials, password manager and authenticator data, and cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.