216.73.217.22

Fileless Python InfoStealer Targeting Exodus

· Published 28/01/2025 10:59 · Modified 28/01/2025 15:30

Export JSON

Essential information

Published
28/01/2025 10:59
Modified
28/01/2025 15:30
Tags
2025-01-28 crypto-wallet exodus infostealer keylogger python
Related entities
1 observables, 8 techniques (mitre), 1 others

Description

A new -based info stealer targeting the crypto wallet has been discovered. This malware employs fileless techniques, clipboard monitoring, and keylogging to capture wallet passwords and sensitive data. It checks for the existence of 'passphrase.json' and, if not found, uses a to capture the victim's password when the password prompt appears. The malware compresses and exfiltrates stolen data in memory via Discord webhooks. It also implements clipboard monitoring to intercept potentially stored passwords. The script's sophisticated design includes password validation checks and targeted window detection for -related activities.

External references