Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
As we saw in our previous research, game-related and other software lures are used to start the infection chain. Some of the detected ZIP names in these recent campaigns include: MOUSE_PI_Trainer_v1.0.zip ... TradingView-Activation-Script-0.9.zip ... Autodesk.zip
The first, sysreq.js, runs PowerShell and WMI commands to check whether the system is a real machine or a virtual one.
It can also inject malicious code into browser processes, bypass Windows User Account Control, persist through scheduled tasks, and pull new command-and-control addresses from Telegram to keep the operation alive after partial takedowns.
Once installed on your PC, NWHStealer can: ... Achieve persistence via scheduled tasks.
The first, sysreq.js, runs PowerShell and WMI commands to check whether the system is a real machine or a virtual one.
Attackers are increasingly abusing alternative JavaScript runtimes like Bun and Deno... The returned code ... is a small eval-loop function that downloads the next stage.
It can also inject malicious code into browser processes, bypass Windows User Account Control, persist through scheduled tasks, and pull new command-and-control addresses from Telegram to keep the operation alive after partial takedowns.
Once installed on your PC, NWHStealer can: ... Achieve persistence via scheduled tasks.
It can also inject malicious code into browser processes, bypass Windows User Account Control, persist through scheduled tasks, and pull new command-and-control addresses from Telegram to keep the operation alive after partial takedowns.
Strings and configurations are encrypted using XOR combined with base64 encoding, making static analysis much harder.
It spreads through Node.js scripts, MSI installers, and fake software downloads hosted on trusted platforms such as GitHub, GitLab, SourceForge, and Itch.io.
It can also inject malicious code into browser processes, bypass Windows User Account Control, persist through scheduled tasks, and pull new command-and-control addresses from Telegram to keep the operation alive after partial takedowns.
The loader runs several PowerShell CIM (Common Information Model) commands and WMI (Windows Management Instrumentation) commands to detect virtual environments... A scoring system is implemented, and based on this score, the loader decides whether to continue with the infection or terminate it.
The first, sysreq.js, runs PowerShell and WMI commands to check whether the system is a real machine or a virtual one. It inspects CPU count, disk space, screen resolution, hardware manufacturers, and even the username, using a scoring system to decide whether to proceed with infection or stop entirely.
It collects system information, steals saved browser data and passwords...
Once inside a system, NWHStealer is highly capable. It collects system information...
The loader runs several PowerShell CIM (Common Information Model) commands and WMI (Windows Management Instrumentation) commands to detect virtual environments... A scoring system is implemented, and based on this score, the loader decides whether to continue with the infection or terminate it.
The first, sysreq.js, runs PowerShell and WMI commands to check whether the system is a real machine or a virtual one. It inspects CPU count, disk space, screen resolution, hardware manufacturers, and even the username, using a scoring system to decide whether to proceed with infection or stop entirely.
The second file, memload.js, handles communication with the attacker’s command-and-control server.
The loader obtains and sends an initial request to the endpoint https://C2-server/api/report ... Then it makes two GET HTTP requests: https://C2-server/api/status?v={BUILD_ID} ... https://C2-server/api/update?v={BUILD_ID}
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer referenced as being distributed through Bun-based infection chains.
An information-stealing malware family referenced as being distributed through Bun-based infection chains.
Rust-based Windows information stealer that is delivered via Node.js/Bun-based loaders, MSI installers, and fake software downloads. It steals system information, browser data and passwords, cryptocurrency wallets, and data from applications such as Discord, Steam, and FileZilla; it can also inject into browser processes, bypass UAC, persist via scheduled tasks, and update C2 infrastructure via Telegram.
Rust-based Windows infostealer distributed through lures such as Node.js scripts, MSI installers, and Bun JavaScript runtime loaders. It collects system information, steals data from browsers, extensions, crypto wallets, FTP and messaging applications, can inject malicious code into browser processes, run additional payloads such as XMRig, attempt UAC bypass, establish persistence via scheduled tasks, and retrieve new C2 addresses from Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.