PULSE NAME
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
WHITE AlienVault 2025-11-07 Modified: 2025-12-07
9
IOCs
LOW VOLUME
A new two-stage malware named LeakyInjector and LeakyStealer has been identified, targeting cryptocurrency wallets and browser history. LeakyInjector uses low-level APIs for injection to avoid detection and injects LeakyStealer into explorer.exe. LeakyStealer implements a polymorphic engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes persistence through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server.
Indicators of Compromise (9)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6e81a3dd21518b8436319fb59801b720 2025-11-07
FileHash-MD5 85a42f527518ec7b089d9c130c0348d5 2025-11-07
FileHash-SHA1 8cac48920f240c442bfc6c57a9c5e6ef41172139 2025-11-07
FileHash-SHA1 a8bf7554363d27deb374c4e2658ac05c60e3baa7 2025-11-07
FileHash-SHA1 ac383f12c3fd1110543efbee85755df0b6a575c1 2025-11-07
FileHash-SHA256 9b8bd9550e8fdb0ca1482f801121113b364e590349922a3f7936b2a7b6741e82 2025-11-07
FileHash-SHA256 dea8653698cea84e063165524c3e8c8141de246a29b9b8de40be3943fd1c6f14 2025-11-07
domain everstead.group 2025-11-07
domain paycnex.com 2025-11-07