🚨 We’re tracking increased #DestinyStealer activity targeting organizations across Europe and the US.
⚠️ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots.
❗️ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams.
The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\\ for data collection. The collected data is then packed into %TEMP%\.zip.
Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host.
👨💻 See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoservice&utm_term=090726
🔍 Pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktotilookup&utm_term=090726#%7B%22query%22:%22threatName:%5C%22destinystealer%5C%22%22,%22dateRange%22:180%7D
⚡️ Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoenterpriselanding&utm_term=090726
IOCs
50008cd78878cb1b3c142e1fd60db55917b233465b8f3f6769ca862902af58bb
ca288e609c5e4be27b95b10c4d11c29d3898ea632739dfeed3586b5049e21f26
3d840505ad13b082d6a8d52399ad52f6f0e79c07f25f55357cda09113010b30a
Domains:
destinystealer[.]com
tipidor-38534[.]portmap[.]host
Exfil URL:
hxxps[:]//destinystealer[.]com/fileicin[.]php
You've seen all posts