Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatLabz researchers found that the padded bytes were irrelevant to running the sample file and determined that threat actor included them to evade detection by security engines.
It seems basic targets such as browser cookies, IDs, and passwords are chosen if the related libraries exist.
The targets for stealing in the settings data are mainly strings related to cryptocurrencies such as browser plugin wallets and open source wallets. It seems basic targets such as browser cookies, IDs, and passwords are chosen if the related libraries exist.
After running, the gathered system information and installed application information is sent back to the C2 server.
The examined instance of RecordBreaker is designed to steal browser information from extensions... using extension IDs provided from the C2 server.
When it first accesses C2, the malware sends the user name, MachineGUID value, and hard-coded key values within the sample and receives the settings data.
When users visit fake shareware sites and click to download, they immediately experience multiple redirects that obfuscate the process for detection by search engines, scanners, and victims, and finally deliver them to a malicious site hosting the threat actor’s intended content. | Once the timeout period is over the loader connects to the remote server requesting a jpg file... once the content is reversed by the malicious program, it transforms into a DLL file.
191 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer distributed through fake shareware sites. It communicates with a C2 server, downloads required libraries, steals browser extension wallet data, system and installed application information, browser cookies, and can capture screenshots.
Infostealer distributed via fake software cracks/installers. It contacts C2 for settings, downloads additional libraries, steals system information, installed programs, screenshots, browser data, and numerous cryptocurrency wallet/browser-extension artifacts, and can also install additional malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.