Researchers reported that the .NET-based August information stealer was used in targeted phishing campaigns against retail customer service and managerial staff, with attackers sending personalized purchase-support lures that delivered malicious Word documents. The documents used macros and PowerShell to filelessly load August from remote byte arrays, while evasion checks looked for analysis environments and tools such as Wireshark and Fiddler. Once installed, August could steal credentials, cookies, documents, wallet.dat files, cryptocurrency wallets, RDP files, and data from browsers, mail, messaging, and FTP applications before reporting host details back to command-and-control servers.
Separate analysis tied August to the emergence of CoalaBot, an HTTP-focused DDoS bot that appears to be built from or heavily derived from August code. CoalaBot was advertised with attack modes including HTTP GET, POST, Slowloris, and Pulse Wave, along with a so-called SMART mode intended to bypass protections such as Cloudflare and BlazingFast. Investigators said CoalaBot was distributed through BetaBot and Andromeda infections, including delivery via the RIG exploit kit in at least one HilltopAds malvertising chain, indicating that the same malware ecosystem was being used both for credential theft and for deploying DDoS capability.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed multiple campaigns in November attributed to TA530 that targeted customer service and managerial staff at retailers with personalized purchase-support themed emails. The attacks used malicious Word macros and PowerShell to filelessly load the August information stealer.
Emerging Threats published rule 2024531 for 'ET TROJAN MSIL/CoalaBot CnC Activity.' The rule provided network detection coverage for CoalaBot command-and-control traffic.
The CoalaBot analysis concluded that the bot appears to be built from or heavily derived from August Stealer, citing very similar panel design and traffic characteristics. This connected the DDoS bot to the earlier August malware family.
A witnessed infection chain to CoalaBot was noted, showing the malware in active distribution. The post says CoalaBot was spread as tasks in BetaBot and Andromeda infections, with Andromeda delivering it via the RIG exploit kit and at least one malvertising chain linked to HilltopAds.
A translated advertisement for 'Coala Http Ddos Bot' was published by a user named Discomrade. The ad described a .NET 2.0 x86 HTTP-focused DDoS bot with multiple flood modes, SSL support for most attack types, optional .onion gates, encrypted traffic, and geofencing to avoid former CIS countries.
Proofpoint analyzed August as a new .NET-based, Confuser-obfuscated information stealer capable of collecting credentials, cookies, documents, RDP files, wallet.dat files, cryptocurrency wallets, and data from multiple applications. The report also documented its evasion checks, host profiling, and custom network obfuscation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.