Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once the environment was prepped, a binary called “sefirah” dropped onto the machine. It’s written in Rust... The payload ran eight data collectors in parallel: Crypto wallets... Discord tokens... Developer credentials... Browser data... Screenshots... File search... Everything was bundled into a JSON package and sent to a command-and-control server
Once the environment was prepped, a binary called “sefirah” dropped onto the machine. It’s written in Rust... The payload ran eight data collectors in parallel: Crypto wallets... Discord tokens... Developer credentials... Browser data... Screenshots... File search... Everything was bundled into a JSON package and sent to a command-and-control server
23 distinct techniques documented for this family, organized by ATT&CK tactic.
A fake repository impersonating OpenAI’s Privacy Filter tool climbed to the top of Hugging Face’s trending list last week... Attackers cloned its documentation almost word-for-word, creating a mirror repository that looked credible enough to fool experienced developers at first glance.
followed by the creation of a scheduled task dressed up as a Microsoft Edge update to lock in SYSTEM-level persistence.
The repository had typosquatted OpenAI's legitimate Privacy Filter release, copied its model card nearly verbatim, and shipped a loader.py file that fetches and executes infostealer malware on Windows machines.
The command, which is executed in an invisible window, downloads a batch file (start.bat) that performs privilege escalation, downloads the final payload (sefirah), adds it to Microsoft Defender's exclusions for it, and executes it.
Browser data: Saved passwords, credit cards, cookies, and autofill data from Chrome, Edge, Firefox, Brave, and any other Chromium or Gecko-based browser on the machine.
Developer credentials: SSH keys, FTP credentials (with specific attention to FileZilla), and VPN configs.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based information stealer delivered via a fake Hugging Face repository impersonating OpenAI’s Privacy Filter. It establishes persistence, evades defenses by disabling AMSI/ETW and adding Defender exclusions, then steals wallet data, Discord tokens, developer credentials, browser secrets, screenshots, and sensitive files before exfiltrating them to C2.
A Rust-based infostealer delivered via a malicious Hugging Face repository. It steals browser data, Discord tokens, cryptocurrency wallets, SSH/FTP/VPN credentials, sensitive local files, system information, and multi-monitor screenshots, then compresses and exfiltrates the data to a C2 server. It also includes anti-analysis checks for virtual machines, sandboxes, debuggers, and analysis tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.