PULSE NAME
Campaign uses infostealers and clippers for financial gain
WHITE AlienVault 2024-08-16 Modified: 2024-09-15
53
IOCs
HIGH VOLUME
Kaspersky has uncovered a complex malware campaign orchestrated by Russian-speaking cybercriminals. The threat actors create sub-campaigns mimicking legitimate projects, using social media to enhance credibility. They host initial downloaders on Dropbox to deliver infostealers like Danabot and StealC, as well as clippers. In addition to distributing malware, the campaigns trick victims into providing credentials and linking cryptocurrency wallets to drain funds. The analysis covers three active sub-campaigns involving multistage malware, process injection, and various evasion techniques.
Indicators of Compromise (1 / 53 total)
All BitcoinAddress URL domain hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL https://tydime.io/api.php' 2024-08-16