SilentDataCollector: Credential and Data Stealer in StopAndProtect
SilentDataCollector is a stealer component that exfiltrates file lists, specific files, and credentials. It includes a keylogger, WhatsApp data exfiltration, and screenshot…
SilentDataCollector is a stealer component that exfiltrates file lists, specific files, and credentials. It includes a keylogger, WhatsApp data exfiltration, and screenshot…
s5cmd is a command-line tool for interacting with cloud storage, used by Ransom Busters to exfiltrate data to cloud storage.
Gofile is a file hosting service used by the StubMaker stealer to upload stolen data as password-protected ZIP archives.
A vulnerability in Zimbra that allows authenticated users to bypass mail forwarding restrictions and exfiltrate email. Discovered by Rapid7 researcher Jonah Burgess.
TmcPayload is an encrypted payload deployed by TmcLoader to exfiltrate stored sensitive data from victim machines. It was part of the evolved…
7-Zip is a legitimate file archiving utility. It was used alongside WinRAR to compress and archive stolen data for exfiltration.
ARToken is a sophisticated phishing kit that ships with features like PRT persistence, mailbox access, BEC automation, and SharePoint exfiltration. It represents…
MinIO is used by GigaWiper for data exfiltration, appearing as normal storage traffic.
ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…
WinRAR is a legitimate file archiving utility. In this campaign, attackers used it to archive stolen data before exfiltration.