GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    sp00ky cR0w 🏴 (cr0w@infosec.exchange)'s status on Tuesday, 16-Sep-2025 23:36:23 JST sp00ky cR0w 🏴 sp00ky cR0w 🏴
    • da_667

    Hey, @da_667, it's still Tuesday.

    https://www.cyfirma.com/research/unmasking-a-python-stealer-xillenstealer/

    #threatIntel

    In conversation about a month ago from infosec.exchange permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 16-Sep-2025 23:36:22 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • da_667

      @cR0w @da_667 lolbins/lollibs?

      In conversation about a month ago permalink
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Tuesday, 16-Sep-2025 23:36:23 JST da_667 da_667
      in reply to

      @cR0w it certainly is.

      In conversation about a month ago permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/214/460/740/185/981/original/d0f808d6259d4c88.png
    • Embed this notice
      sp00ky cR0w 🏴 (cr0w@infosec.exchange)'s status on Tuesday, 16-Sep-2025 23:36:23 JST sp00ky cR0w 🏴 sp00ky cR0w 🏴
      in reply to
      • da_667

      @da_667 LMFAO. It worked fine for me in Reader Mode on LibreWolf / Firefox. Here's the summary:

      EXECUTIVE SUMMARY

      Cyfirma’s threat intelligence assessment of XillenStealer identifies it as an open-source, Python-based information stealer publicly available on GitHub. The malware is designed to harvest sensitive system and user data through modular scripts that utilize native libraries and Windows functions for reconnaissance and collection. Its core capabilities include extracting host identifiers, hardware specifications, Cryptocurrency credentials, and network configurations, as well as retrieving browser-stored credentials. Additionally, it incorporates screenshot capture functionality to broaden the scope of compromised information.

      The collected data is consolidated into structured outputs, frequently archived for streamlined handling, and exhibits automated exfiltration mechanisms to external communication channels, such as a Telegram bot. CYFIRMA’s analysis highlights that the open-source availability of XillenStealer not only reduces the barrier for adversaries to adopt and customize it for malicious operations but also provides defenders with valuable insights to study its architecture for enhanced detection, mitigation, and threat-hunting strategies.

      In conversation about a month ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.