Editbot Stealer is a new malicious campaign that steals browser passwords and cookies. It uses WinRAR archive files with minimal detection to perform a multi-stage attack. The attackers lure users to deceptive websites by claiming to have a defective product to be sent back. The attack involves a BAT file and a JSON file for initial stages, followed by PowerShell commands. The stolen information is stored in a text file named "pass.txt" and is exfiltrated through telegram bots. #Editbot Stealer #BrowserPasswords #Cookies #CyberSecurity
Discussion
No replies yet.