Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"Мета это программа-стиллер, ворующий пароли и другие сохраненные данные с компьютера."
Keylogging ( T1056.001, Credential Access / Collection ) - перехват нажатий клавиш для захвата вводимых вручную паролей, включая те, что не сохраняются в браузере.
Steal Web Session Cookie ( T1539, Credential Access ) - кража session cookies, позволяющая обойти MFA. Атакующий реплеит cookie и получает доступ к сессии без пароля и второго фактора.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Инфостилер, связанный с кражей email/password из конфискованных стилер-логов.
Infostealer mentioned as part of prior Booking.com-themed hospitality targeting campaigns (contextual reference; not the primary payload in PHALT#BLYX).
An infostealer that steals passwords and other saved data from infected computers. The interview states customer logs are sent directly to the client panel and says the project began in 2021.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.