home.social

#informationtheft — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #informationtheft, aggregated by home.social.

fetched live
  1. Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

    Pulse ID: 6a7951a3cb8e961a30c583bb
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:20:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InformationTheft #Malware #OTX #OpenThreatExchange #Python #bot #Tr1sa111

  2. Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

    Pulse ID: 6a7951a3cb8e961a30c583bb
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:20:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #InformationTheft #Malware #OTX #OpenThreatExchange #Python #bot #Tr1sa111

  3. Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

    Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...

    Pulse ID: 6a74beb7cd2fbf6d191ba7c9
    Pulse Link: otx.alienvault.com/pulse/6a74b
    Pulse Author: AlienVault
    Created: 2026-08-06 17:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault

  4. Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware

    Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...

    Pulse ID: 6a74beb7cd2fbf6d191ba7c9
    Pulse Link: otx.alienvault.com/pulse/6a74b
    Pulse Author: AlienVault
    Created: 2026-08-06 17:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault

  5. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  6. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault