"PXA Stealer has the capability to decrypt the victim's browser master password and uses it to steal the stored credentials of various online accounts."
"The connections to Vietnam stem from the presence of Vietnamese comments and a hard-coded Telegram account named 'Lone None' in the stealer program."
"The tools shared by the attacker in the group are automated utilities designed to manage several user accounts, including a Hotmail batch creation tool."
"Cisco Talos observed the attacker selling Facebook and Zalo account credentials, and SIM cards in the Telegram channel 'Mua Bán Scan MINI.'"
Collection
[
|
...
]