PULSE NAME
Infostealer Campaign Using Trading App as Lure
WHITE Kimsuky AlienVault 2026-05-20 Modified: 2026-05-21
17
IOCs
MEDIUM VOLUME
A sophisticated infostealer operation was discovered masquerading as a cryptocurrency trading application called Tralert FX. The malicious MSI installer achieved only 3/52 AV detections by using a valid EV code signing certificate from a likely front company, AgilusTech LLC. The campaign has been active since June 2025, utilizing a three-module malware kit that includes system reconnaissance, keylogging, and browser credential theft capabilities. Stolen data is exfiltrated through five GitLab repositories via automated git commits on 30-minute cycles. Hardcoded credentials exposed the entire backend infrastructure, revealing over 4,100 commits, 90+ compromised hosts, and ongoing victim compromise. The operation demonstrates clear financial motivation with focus on cryptocurrency traders for account takeover. Three ProtonMail-linked GitLab accounts operate the infrastructure, assessed as a single operator or small team. The final payload is MoonPeak, a custom variant of XenoRAT.
Indicators of Compromise (4 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0 2026-05-20
FileHash-SHA256 3c356065e32ac8cbc6ec330581c7c343bf2d5567695f3a015a0ae95908a7ed6b 2026-05-20
FileHash-SHA256 528b004407d32bbc6299540a7a9fd98a3037070d34b56f14813aaaa29820b13d 2026-05-20
FileHash-SHA256 eaba341f94e700ff470e7a8fb3fe596f601ff54a8415103fa102520ec4bbd5e9 2026-05-20