216.73.216.6

Infostealer Campaign Using Trading App as Lure

· Published 20/05/2026 11:12 · Modified 21/05/2026 16:11

Export JSON

Essential information

Published
20/05/2026 11:12
Modified
21/05/2026 16:11
Tags
2026-05-20 code-signing-abuse cryptocurrency dprk-nexus gitlab exfiltration infostealer moonpeak trading app lure xenorat
Related entities
4 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 12 others

Description

A sophisticated operation was discovered masquerading as a trading application called Tralert FX. The malicious MSI installer achieved only 3/52 AV detections by using a valid EV code signing certificate from a likely front company, AgilusTech LLC. The campaign has been active since June 2025, utilizing a three-module malware kit that includes system reconnaissance, keylogging, and browser credential theft capabilities. Stolen data is exfiltrated through five GitLab repositories via automated git commits on 30-minute cycles. Hardcoded credentials exposed the entire backend infrastructure, revealing over 4,100 commits, 90+ compromised hosts, and ongoing victim compromise. The operation demonstrates clear financial motivation with focus on traders for account takeover. Three ProtonMail-linked GitLab accounts operate the infrastructure, assessed as a single operator or small team. The final payload is , a custom variant of .

External references