PULSE NAME
CoinLurker: The Stealer Powering the Next Generation of Fake Updates
WHITE CoinLurker AlienVault 2024-12-17 Modified: 2024-12-17
62
IOCs
HIGH VOLUME
CoinLurker is a sophisticated stealer designed to exfiltrate data while evading detection. Written in Go, it employs advanced obfuscation and anti-analysis techniques, making it highly effective in modern cyberattacks. The malware is delivered through fake update campaigns, leveraging deceptive entry points that exploit user trust. It uses Microsoft Edge Webview2 as a stager and employs a multi-stage chain involving Binance Smart Contracts and Bitbucket repositories to conceal its payload. CoinLurker targets cryptocurrency wallets and financial applications, systematically enumerating directories to access sensitive user data. Its layered injection tactics and obfuscated functions make it challenging for analysts to reverse-engineer its logic.
Indicators of Compromise (6 / 62 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0a0fe5b8b0df295f8ecbf32355ea846d 2024-12-17
FileHash-MD5 55dfa074a62def3eb4733078ad504845 2024-12-17
FileHash-MD5 601c10036f779d66d51d041db843527f 2024-12-17
FileHash-MD5 6079d484d0636beb2d413932ac5a1bec 2024-12-17
FileHash-MD5 9f73132fee32e4e0b0f4ef0843abffaa 2024-12-17
FileHash-MD5 da881ee6a5018f2c97290440f9c537b4 2024-12-17