PULSE NAME
Pentagon Stealer: Go and Python Malware Targeting Crypto
WHITE AlienVault 2025-04-30 Modified: 2025-04-30
21
IOCs
MEDIUM VOLUME
Pentagon Stealer is an evolving malware threat that exists in both Python and Golang versions. It primarily targets browser credentials, cookies, crypto wallet data, and messaging app tokens. The malware exploits browser debug modes to bypass encryption and injects into crypto wallets to steal sensitive information. Initially spread through typosquatting, it has appeared under various names like 1312, Acab, Vilsa, and BLX stealer. The Golang version expanded its capabilities to target more browsers. Pentagon Stealer uses HTTP requests for C2 communication and is often part of larger attack chains. While relatively simple, its persistent development and integration into various campaigns make it an ongoing threat to users' financial and personal data.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Pentagon Stealer 1312 Stealer Acab Stealer Vilsa Stealer BLX Stealer Purecrypter
Indicators of Compromise (21)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
URL https://pentagon.cy/atomic 2025-04-30
FileHash-MD5 a1726ff80b020aa291bdcbb21159c618 2025-04-30
FileHash-SHA1 51c9978e60995174ed2b6b8cc5e8e1a973b66337 2025-04-30
FileHash-SHA256 0411589551ab684892e3cc776674df0f07bcdbb931c29da93c2afd08fe077336 2025-04-30
URL http://1312services.ru/delivery. 2025-04-30
URL http://1312services.ru/pw 2025-04-30
URL http://1312services.ru/webdata 2025-04-30
URL http://funcaptcha.ru/delivery. 2025-04-30
URL http://pentagon.cy/create_log 2025-04-30
URL http://pentagon.cy/paste?userid= 2025-04-30
URL https://pentagon.cy/create_log 2025-04-30
URL https://pentagon.cy/exodus 2025-04-30
URL https://pentagon.cy/log_data 2025-04-30
URL https://pentagon.cy/log_files 2025-04-30
URL https://pentagon.cy/wallet_injection 2025-04-30
domain 1312services.ru 2025-04-30
domain 1312stealing.ru 2025-04-30
domain biteblob.com 2025-04-30
domain funcaptcha.ru 2025-04-30
domain pentagon.cy 2025-04-30
domain stealer.cy 2025-04-30