PULSE NAME
CoolClient Updates to Deploy Browser Login Data Stealer
WHITE cryptocti 2026-01-29 Modified: 2026-02-28
22
IOCs
MEDIUM VOLUME
The CoolClient malware is distributed through DLL sideloading, leveraging legitimate signed executables to load malicious DLLs and evade security detection. This technique allows the attackers to establish persistence while appearing as trusted software activity on the compromised system.
Indicators of Compromise (2 / 22 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname account.hamsterxnxx.com 2026-01-29
hostname japan.lenovoappstore.com 2026-01-29