🚨 We’re tracking increased #DestinyStealer activity targeting organizations across Europe and the US. ⚠️ At the code level, it acts as an all-in-one grabber, with clear code continuity from StormKitty, collecting browser data, cookies, passwords, wallet extension storage, Outlook, VPN and FileZilla data, Wi-Fi profiles, and desktop screenshots. ❗️ Some samples were still undetected on VirusTotal at the time of analysis, while others lacked clear attribution, making behavior-based analysis critical for SOC teams. The attack starts with an IP check via ipinfo[.]io. The malware then creates a temporary directory at %TEMP%\\ for data collection. The collected data is then packed into %TEMP%\.zip. Exfiltration uses two parallel channels: HTTP to destinystealer[.]com/fileicin[.]php and raw TCP to tipidor-38534[.]portmap[.]host. 👨‍💻 See the full execution chain and collect IOCs to speed up detection and cut response time: https://app.any.run/tasks/01f70f9e-642d-46fa-b485-cf67dced6436/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoservice&utm_term=090726 🔍 Pivot from IOCs and subscribe to Query Updates to proactively track evolving attacks: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktotilookup&utm_term=090726#%7B%22query%22:%22threatName:%5C%22destinystealer%5C%22%22,%22dateRange%22:180%7D ⚡️ Learn how #ANYRUN Sandbox helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=destiny_stealer&utm_content=linktoenterpriselanding&utm_term=090726 IOCs 50008cd78878cb1b3c142e1fd60db55917b233465b8f3f6769ca862902af58bb ca288e609c5e4be27b95b10c4d11c29d3898ea632739dfeed3586b5049e21f26 3d840505ad13b082d6a8d52399ad52f6f0e79c07f25f55357cda09113010b30a Domains: destinystealer[.]com tipidor-38534[.]portmap[.]host Exfil URL: hxxps[:]//destinystealer[.]com/fileicin[.]php