Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Les identifiants ciblés comprennent clés IAM, jetons OIDC, jetons Entra ID, comptes de service GCP, PATs et clés API; la liste inclut T1078 — Valid Accounts.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
Les cibles incluent des jetons OIDC AWS SSO, jetons Entra ID et refresh tokens, jetons GCP, GitHub App/OAuth/PAT, jetons GitLab Runner et jetons OAuth d’outils IA.
“If malware steals that token and an attacker loads it into another browser, the service may treat the attacker as the authenticated user.” The listed targets include GitHub and ChatGPT browser-session cookies.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer cité parmi les principales familles impliquées dans le vol de credentials cloud, de code et d'outils d'IA.
An infostealer cited as a major source of infected endpoints containing cloud credentials, API keys, browser sessions, and developer secrets.
Named as a malware strain disseminated using ITG23-associated crypters.
An information stealer mentioned as one of the newer malware families seen with ITG23-related crypters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.