Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Running this script against a modified version of Legion Stealer attributed to actor CobraEgy was quite helpful in reducing the volume of noise.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"Session token and cookie theft has become the primary objective of stealer malware... When attackers steal active session cookies, MFA becomes irrelevant"; and "listings typically include browser passwords, cookies, and session tokens."
Credential exposure is a huge problem: organizations often unknowingly upload service credentials to publicly accessible code sharing services like Docker Hub, GitHub, or Pastebin... TeamTNT’s credential harvesting scripts... The hardcoded username and password were used to connect to a C2 server to upload the data harvested from the system.
"Improved decryption of the latest versions of Chromium-based browsers (144+)... Now different versions of Chrome (before 143 / after 144) are decrypted with different elevators, and the method is selected dynamically"; and "listings typically include browser passwords, cookies, and session tokens."
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C# infostealer that exfiltrates stolen data via Discord webhooks (using Discord as free C2/exfil infrastructure); advertised capabilities include anti-VM checks and disruptive host actions like disabling AV and Task Manager.
A cloud-focused stealer script analyzed via word-frequency methods; the content also notes it shares a PayPal validator URL pattern used by other cloud attack tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.