CoinLurker is a newly reported stealer malware observed in a campaign disclosed by Morphisec. Based on the available reporting, CoinLurker is delivered via multiple initial access vectors, including malvertising and phishing. No additional high-confidence technical details (e.g., specific data theft targets, persistence mechanisms, C2 infrastructure, file hashes, or other IOCs), targeted geographies/industries beyond general mentions, or threat-actor attribution are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based stealer using obfuscation and anti-analysis techniques; delivered via bogus software update lures leveraging WebView2.
CoinLurker is a malware distributed through various vectors including rogue apps, malvertising, phishing emails, fake CAPTCHA prompts, rogue websites, and social media. Its specific functionality is not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.