: Classified as an infostealer , this malware targets personal data stored on the infected machine. Common Behaviors :
Analysis using tools like the Hybrid Analysis Sandbox and ANY.RUN highlights several red flags in the executable’s code:
: Steals Discord tokens and Telegram sessions to compromise user accounts.
: Because these tools target saved passwords, reset all critical account credentials (banking, email, social media) from a known clean device.
: Targets browser login data, passwords, and autofill information.