PULSE NAME
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
WHITE AlienVault 2025-11-07 Modified: 2025-12-07
9
IOCs
LOW VOLUME
A new two-stage malware named LeakyInjector and LeakyStealer has been identified, targeting cryptocurrency wallets and browser history. LeakyInjector uses low-level APIs for injection to avoid detection and injects LeakyStealer into explorer.exe. LeakyStealer implements a polymorphic engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes persistence through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server.
Indicators of Compromise (2 / 9 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6e81a3dd21518b8436319fb59801b720 2025-11-07
FileHash-MD5 85a42f527518ec7b089d9c130c0348d5 2025-11-07