RussianPanda 🐼 🇺🇦(@RussianPanda9xx) 's Twitter Profile Photo

Unraveling Not AZORult but Koi Loader: A Precursor to Koi Stealer

Did some analysis on which ultimately led to . Warning ⚠️It is not AZORult.

The blog: esentire.com/blog/unravelin…

eSentire Threat Intel

Unraveling Not AZORult but Koi Loader: A Precursor to Koi Stealer

Did some analysis on #KoiLoader which ultimately led to #KoiStealer. Warning ⚠️It is not AZORult. 

The blog: esentire.com/blog/unravelin…

@esthreat
account_circle
Brad(@malware_traffic) 's Twitter Profile Photo

Unit 42 A of the / infection traffic and the associated malware samples are available at malware-traffic-analysis.net/2024/04/04/ind…

@Unit42_Intel A #pcap of the #KoiLoader/#KoiStealer  infection traffic and the associated malware samples are available at  malware-traffic-analysis.net/2024/04/04/ind…
account_circle
Unit 42(@Unit42_Intel) 's Twitter Profile Photo

2024-04-04 (Thursday): We generated an infection in a lab environment based on the latest round of / activity. Initial bank-themed lures started earlier this week on 2024-04-02. Some indicators available at bit.ly/3PQut3r

2024-04-04 (Thursday): We generated an infection in a lab environment based on the latest round of #KoiLoader/#KoiStealer activity. Initial bank-themed lures started earlier this week on 2024-04-02. Some indicators available at bit.ly/3PQut3r

#Unit42ThreatIntel
account_circle
Brad(@malware_traffic) 's Twitter Profile Photo

\_(ʘ_ʘ)_/ We've been having a discussion about this, it's actually / . The AZORult identification is was based on an article from 2023, but the code and the traffic doesn't really match what we'd seen before with AZORult. Thread: twitter.com/RussianPanda9x…

account_circle
h4cktiv4t0r(@h4cktiv4t0r) 's Twitter Profile Photo

RussianPanda 🐼 🇺🇦 Hello, Ann. There's this new kind of malware called KoiStealer that has popped up in the cyber world lately. It's a pretty nasty piece of software because not only does it steal information, but it also has a special liking for getting into cryptocurrency wallets.

account_circle
Kyle Cucci(@d4rksystem) 's Twitter Profile Photo

RussianPanda 🐼 🇺🇦 Here is some more info: securityaffairs.com/144092/malware…

We have been tracking KoiLoader/KoiStealer as well. It's not very common, but it's a thing.

account_circle