PULSE NAME
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
WHITE AlienVault 2025-11-07 Modified: 2025-12-07
9
IOCs
LOW VOLUME
A new two-stage malware named LeakyInjector and LeakyStealer has been identified, targeting cryptocurrency wallets and browser history. LeakyInjector uses low-level APIs for injection to avoid detection and injects LeakyStealer into explorer.exe. LeakyStealer implements a polymorphic engine to modify its memory area at runtime. Both stages were signed with valid Extended Validation certificates. The malware performs reconnaissance on infected machines, targeting multiple crypto wallets, including browser extensions, and searches for browser history files from various browsers. It establishes persistence through registry manipulation and beacons to the C2 server at regular intervals. The malware exfiltrates sensitive data and can execute additional commands received from the C2 server.
Indicators of Compromise (2 / 9 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 9b8bd9550e8fdb0ca1482f801121113b364e590349922a3f7936b2a7b6741e82 2025-11-07
FileHash-SHA256 dea8653698cea84e063165524c3e8c8141de246a29b9b8de40be3943fd1c6f14 2025-11-07