Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SentinelLabs, in collaboration with Checkmarx, has been tracking the activity and evolution of a threat actor dubbed “JuiceLedger”. In early 2022, JuiceLedger began running relatively low-key campaigns, spreading fraudulent Python installer applications with ‘JuiceStealer’, a .NET application designed to steal sensitive data from victims’ browsers.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Besides PyPi, the functionality of EvilProxy also supports GitHub and npmjs ... enabling supply chain attacks via advanced phishing campaigns.
Some of those phishing attacks appear to have been successful, leading to the compromise of legitimate code packages whose contributors credentials were compromised... Compromised packages uploaded by JuiceLedger in the August campaign contain a short code snippet, responsible for downloading and executing a signed variant of JuiceStealer.
In August 2022, the threat actor engaged in poisoning open-source packages as a way to target a wider audience with the infostealer through a supply chain attack... The attack on PyPI in August involves a far more complex attack chain, including phishing emails to PyPI developers... On August 24, 2022, PyPi published details of an ongoing phishing campaign targeting PyPi users.
The file contains an LNK file ... triggering the execution of an obfuscated PowerShell command...
The file contains an LNK file ... triggering the execution of an obfuscated PowerShell command, which in turn runs mstha to load an .HTA file...
The file contains an LNK file ... triggering the execution of an obfuscated PowerShell command, which in turn runs mstha to load an .HTA file...
This sample iterates over processes containing the word “chrome”, shuts them down and then searches for Google Chrome Extension log files. The infostealer iterates over logs that contain the word “vault”, possibly searching for cryptocurrency vaults... This version of the infostealer... also searches for Google Chrome passwords, querying Chrome SQLite files.
This sample iterates over processes containing the word “chrome”, shuts them down... and reports back to an embedded C2 server over HTTP.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer payload used as a final-stage payload in a phishing attack against PyPI contributors, described as related to EvilProxy actors.
A .NET infostealer used by JuiceLedger in fake installers, phishing, typosquatted packages, and PyPI supply-chain attacks. It steals sensitive browser data, including Chrome extension logs, Chrome passwords via SQLite files, and later added support for additional browsers as well as Discord. It reports stolen data back to embedded C2 infrastructure over HTTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.