LeakyInjector is a malware family observed alongside LeakyStealer in attacks targeting cryptocurrency owners. Reported as a second-stage malware family, it is designed to support theft operations against cryptocurrency-related targets. Its documented behavior includes using low-level APIs for process injection to evade detection and injecting LeakyStealer into explorer.exe. The associated campaign targeted cryptocurrency wallets and browser history. Public reporting cited in the source material comes from Hybrid Analysis and other cybersecurity researchers. High-confidence details in the provided content do not identify a specific threat actor, platform scope beyond the explorer.exe injection behavior, or concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LeakyInjector is a loader malware that uses low-level injection techniques to evade detection and deploys LeakyStealer on infected systems. It is part of a malware duo targeting crypto wallets and browser data.
LeakyInjector is a malware loader used to deliver additional malicious payloads, including information stealers, targeting cryptocurrency owners.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.