PULSE NAME
IOC - LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
WHITE celestre 2025-11-12 Modified: 2025-11-12
7
IOCs
LOW VOLUME
Hybrid Analysis has analyzed a new two-stage malware that we’re naming LeakyInjector and LeakyStealer. The duo performs reconnaissance on an infected machine and targets multiple crypto wallets, including browser extensions corresponding to crypto wallets. The malware also looks for browser history files from Google Chrome, Microsoft Edge, Brave, Opera, and Vivaldi.
Indicators of Compromise (2 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 88e0c1652eb91c517a5fec9d356c7f30c0136d544f5d55ac37f20c5612134efb 2025-11-12
FileHash-SHA256 9b8bd9550e8fdb0ca1482f801121113b364e590349922a3f7936b2a7b6741e82 2025-11-12