← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
The recent infostealer campaign attributed to the DPRK-nexus actor known as VELVET CHOLLIMA employs a fake cryptocurrency trading application called Tralert FX. This malware distribution method includes an MSI installer that integrates a multi-module infostealer with a notably low AV detection rate of only 3 out of 52. The campaign highlights the use of valid EV code signing certificates from a potentially front company, AgilusTech LLC, to enhance the malware’s legitimacy and evade detection.
MITRE ATT&CK & Malware Families
Indicators of Compromise (21)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | f10d35fedb6aa986cef4c113edfdef26 | — | 2026-05-15 | |
| FileHash-SHA1 | ed02996ba97457166406d1d3230ef177fec67913 | — | 2026-05-15 | |
| FileHash-SHA256 | 384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0 | — | 2026-05-15 | |
| FileHash-SHA256 | 3c356065e32ac8cbc6ec330581c7c343bf2d5567695f3a015a0ae95908a7ed6b | — | 2026-05-15 | |
| FileHash-SHA256 | 528b004407d32bbc6299540a7a9fd98a3037070d34b56f14813aaaa29820b13d | — | 2026-05-15 | |
| FileHash-SHA256 | eaba341f94e700ff470e7a8fb3fe596f601ff54a8415103fa102520ec4bbd5e9 | — | 2026-05-15 | |
| IPv4 | 161.97.113.34 | CC=DE ASN=AS51167 contabo gmbh | 2026-05-15 | |
| IPv4 | 91.107.246.107 | CC=IR ASN=AS24940 hetzner online gmbh | 2026-05-15 | |
| URL | http://161.97.113.34:3001 | — | 2026-05-15 | |
| domain | endava.online | — | 2026-05-15 | |
| domain | talert.online | — | 2026-05-15 | |
| domain | talert.site | — | 2026-05-15 | |
| domain | talert.space | — | 2026-05-15 | |
| domain | talert.store | — | 2026-05-15 | |
| domain | tralert.online | — | 2026-05-15 | |
| domain | tralert.site | — | 2026-05-15 | |
| domain | tralert.store | — | 2026-05-15 | |
| domain | tralert7.com | — | 2026-05-15 | |
| domain | trumpalert.store | — | 2026-05-15 | |
| domain | why-db-sometimes-fails.md | — | 2026-05-15 | |
| rur243@proton.me | — | 2026-05-15 |