PULSE NAME
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
WHITE AlienVault 2025-11-07 Modified: 2025-12-07
9
IOCs
LOW VOLUME
A new two-stage malware named LeakyInjector and LeakyStealer has been identified, targeting cryptocurrency wallets and browser history. LeakyInjector uses low-level APIs for injection to avoid detection and injects LeakyStealer into explorer.exe. LeakyStealer implements a polymorphic engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes persistence through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server.
Indicators of Compromise (3 / 9 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 8cac48920f240c442bfc6c57a9c5e6ef41172139 2025-11-07
FileHash-SHA1 a8bf7554363d27deb374c4e2658ac05c60e3baa7 2025-11-07
FileHash-SHA1 ac383f12c3fd1110543efbee85755df0b6a575c1 2025-11-07