#informationtheft — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #informationtheft, aggregated by home.social.
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Pulse ID: 6a7951a3cb8e961a30c583bb
Pulse Link: https://otx.alienvault.com/pulse/6a7951a3cb8e961a30c583bb
Pulse Author: Tr1sa111
Created: 2026-08-10 04:20:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InformationTheft #Malware #OTX #OpenThreatExchange #Python #bot #Tr1sa111
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Pulse ID: 6a7951a3cb8e961a30c583bb
Pulse Link: https://otx.alienvault.com/pulse/6a7951a3cb8e961a30c583bb
Pulse Author: Tr1sa111
Created: 2026-08-10 04:20:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InformationTheft #Malware #OTX #OpenThreatExchange #Python #bot #Tr1sa111
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...
Pulse ID: 6a74beb7cd2fbf6d191ba7c9
Pulse Link: https://otx.alienvault.com/pulse/6a74beb7cd2fbf6d191ba7c9
Pulse Author: AlienVault
Created: 2026-08-06 17:04:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...
Pulse ID: 6a74beb7cd2fbf6d191ba7c9
Pulse Link: https://otx.alienvault.com/pulse/6a74beb7cd2fbf6d191ba7c9
Pulse Author: AlienVault
Created: 2026-08-06 17:04:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault