Just Another Blue Teamer · @LeeArchinal
128 followers · 193 posts · Server ioc.exchange

Among the stealers that Cisco Talos Intelligence Group has observed, the is a new one that appears to focus on browser credential theft with its straightforward techniques. It is capable of gathering host information, screenshots, cached browser credentials, and files stored on the system. It then creates its own directory and stores credentials in a passwords.txt file and screenshots then zips all the data up and exfiltrates it using Simple Mail Transfer Protocol (SMTP). PLUS, as an added bonus, the research team observed some operational security (OPSEC) failures by the adversary which led to some personal accounts that could be associated with the threat actor! Enjoy and Happy Hunting!

SapphireStealer: Open-source information stealer enables credential and data theft
blog.talosintelligence.com/sap

#sapphirestealer #cybersecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting #readoftheday

Last updated 1 year ago

Mr.Trunk · @mrtrunk
11 followers · 18726 posts · Server dromedary.seedoubleyou.me
Aida Akl · @AAKL
411 followers · 752 posts · Server noc.social
Jon Greig · @jgreig
122 followers · 602 posts · Server ioc.exchange

Cisco Talos found hackers are modifying the open source code of SapphireStealer, adding tools and functions that make it easier to steal data

therecord.media/saphirestealer

#sapphirestealer #cisco

Last updated 1 year ago