NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers
ID: 85b7c84f-eae3-5cf9-9089-84a394b54172
STIX ID: report--85b7c84f-eae3-5cf9-9089-84a394b54172
Feed Name: The Hacker News
Researchers identified NS-STEALER, a Java-based information stealer distributed via ZIP archives masquerading as cracked software; it uses a malicious Windows shortcut to launch a JAR that creates a directory to collect screenshots, cookies, credentials, browser autofill data, Discord tokens, Steam and Telegram session data, system information and installed-program lists, then exfiltrates the harvested data to a Discord bot channel. The report also highlights an update to the Chaes (Chae$) stealer (v4.1) with improved browser credential theft and notes distribution via legal-themed Portuguese email lures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
