Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Les capacités de collecte couvrent les cookies de navigateurs Chromium et Firefox; le panneau opérateur permet aussi le filtrage des logs par cookies.
Les capacités de collecte incluent le « profilage système ».
Le file-grabber cible spécifiquement les répertoires Desktop, Downloads et Documents.
Bee Stealer dispose d’un « File-grabber ciblant Desktop, Downloads et Documents » et collecte aussi des données de navigateurs, messagerie, clients email et portefeuilles.
Les capacités annoncées incluent la « Capture d’écran et profilage système ».
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows infostealer sold as MaaS. Version 2.1 steals browser cookies, credentials, browsing and autofill data, email/messaging-client data, password-manager data, cryptocurrency-service and wallet data, files from Desktop/Downloads/Documents, screenshots, and system-profile information. It explicitly collects Codex and Claude authentication data and conversation histories. After exfiltration, operator infrastructure uses an 'AI PC profile' neural-network feature to create English and Russian victim profiles for prioritizing high-value victims.
Windows information stealer sold as malware-as-a-service. It collects browser cookies, saved logins, browsing and autofill data, browser extensions, application data, system-profile information, screenshots, and selected files from Desktop, Downloads, and Documents. It targets authentication data and chat histories from Codex and Claude, and its operator service uses AI-assisted profiling of exfiltrated logs to prioritize valuable victims and accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.