PULSE NAME
CoinLurker: The Stealer Powering the Next Generation of Fake Updates
WHITE CoinLurker AlienVault 2024-12-17 Modified: 2024-12-17
62
IOCs
HIGH VOLUME
CoinLurker is a sophisticated stealer designed to exfiltrate data while evading detection. Written in Go, it employs advanced obfuscation and anti-analysis techniques, making it highly effective in modern cyberattacks. The malware is delivered through fake update campaigns, leveraging deceptive entry points that exploit user trust. It uses Microsoft Edge Webview2 as a stager and employs a multi-stage chain involving Binance Smart Contracts and Bitbucket repositories to conceal its payload. CoinLurker targets cryptocurrency wallets and financial applications, systematically enumerating directories to access sensitive user data. Its layered injection tactics and obfuscated functions make it challenging for analysts to reverse-engineer its logic.
Indicators of Compromise (6 / 62 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 5231f97233076af0846590d7d0386bf78797bd22 2024-12-17
FileHash-SHA1 5db82ea4080c2ed5a647f6d293b8b8663e77f421 2024-12-17
FileHash-SHA1 81c1f12a9f1d817b8f73549c7b5397d82181c413 2024-12-17
FileHash-SHA1 a38196d2ddf819920372759cad512434440fc4b1 2024-12-17
FileHash-SHA1 deea47ac9a0d58170451691634dd67447d1483fc 2024-12-17
FileHash-SHA1 e766d6750f7ca24295dfe985916fa76940a5decd 2024-12-17