#MonsterV2
🚨A Threat Actor is Promoting MonsterV2 HVNC Malware
September 22, 2025 at 5:28 PM
MonsterV2 has many capabilities, but seems to function primarily as a stealer and a loader.
June 5, 2025 at 9:07 PM
We recently discovered an infostealer in our data that we originally dubbed "Aurotun," named for a misspelling of "autorun" in its strings.

After collab w/ @intel471.bsky.social, @malwareindepth.com & others, we believe this malware is actually MonsterV2, a newer version of an existing infostealer.
June 5, 2025 at 9:07 PM
Example hashes:
666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e

b869941a9c476585bbb8f48f7003d158c71e44038ceb2628cedb231493847775

Signatures:
ET sig: 2061200 - ET MALWARE MonsterV2 Stealer CnC Checkin
June 5, 2025 at 9:07 PM
6/ TAG-150 also deploys other malware families, including #SectopRAT, #WarmCookie, #HijackLoader, and #NetSupportRAT, as well as numerous stealers: #Stealc, #RedLine, #Rhadamanthys, #DeerStealer, #MonsterV2, and more.
September 4, 2025 at 3:05 PM
MonsterV2 can also act as a loader—we've seen it drop new variants of StealC and Rhadamanthys.

In addition, some samples of MonsterV2 check to see if the target resides in a CIS country (RU;BY;UA;KZ;UZ;TM;KG;AM;TJ;MD;LV;LT;EE).

It checks this to prevent infection of targets in these countries.
June 5, 2025 at 9:07 PM
🚨 Threat Intel Alert: MonsterV2 HVNC just got an update – this multifunctional malware (Botnet/HVNC/HCDP/Stealer/RAT/etc.) now includes:

[+] Cookie export in JSON via stealer panel
[=] Lib updates (panel + daemon)
[=] Error message fixes
#infosec #malware #threatintel
July 27, 2025 at 6:48 AM
TA585 and MonsterV2: The Rise of Self-Reliant Cybercrime in 2025

Introduction In 2025, cybersecurity researchers have identified a new threat actor, TA585, whose operations are redefining the landscape of cybercrime. Unlike traditional malware groups that rely heavily on third-party services,…
TA585 and MonsterV2: The Rise of Self-Reliant Cybercrime in 2025
Introduction In 2025, cybersecurity researchers have identified a new threat actor, TA585, whose operations are redefining the landscape of cybercrime. Unlike traditional malware groups that rely heavily on third-party services, TA585 independently manages every stage of its attacks—from infrastructure deployment and email delivery to malware installation. Central to its campaigns is MonsterV2, a sophisticated malware suite that combines remote access, credential theft, and payload delivery into one formidable package.
undercodenews.com
October 14, 2025 at 6:53 PM
State: New Jersey
Reported Date: 07/17/2025
PDF URL: https://www.cyber.nj.gov/Home/Components/News/News/1753/214
Title: ClickFix Leading to MonsterV2 Infostealer
July 18, 2025 at 2:31 AM
The Proofpoint Threat Research Team described the threat activity cluster as sophisticated, leveraging web injections and filtering checks as part of its attack chains. thehackernews.com/2025/10/rese...
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain
Researchers link TA585 to MonsterV2 RAT stealer delivered via IRS-themed phishing, JavaScript injects, and GitHub lures.
thehackernews.com
October 14, 2025 at 12:18 PM
Advisory: We've observed a new iteration of the ClickFix phishing campaign with an email claiming users must confirm their identity through a link leading right to a malicious injection script installing the MonsterV2 Infostealer.

Learn more: https://loom.ly/WgL-664
July 21, 2025 at 7:02 PM
TA585 Hackers Uses Unique Web Injection Technique to Deliver MonsterV2 Malware Targeting Windows Systems
TA585 Hackers Uses Unique Web Injection Technique to Deliver MonsterV2 Malware Targeting Windows Systems
cybersecuritynews.com
October 14, 2025 at 2:37 PM
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain
thehackernews.com
October 14, 2025 at 7:06 AM
📢 Le groupe TA585 diffuse le malware MonsterV2 dans une opération avancée
📝 Selon Infosecurity Magazine, un **nouveau groupe cybercriminel** baptisé **TA585** a été ide…
https://cyberveille.ch/posts/2025-10-16-le-groupe-ta585-diffuse-le-malware-monsterv2-dans-une-operation-avancee/ #IOC #Cyberveille
October 18, 2025 at 2:00 AM
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain

Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585 that has been observed delivering an off-the-shelf malware called MonsterV2 via phishing campaigns.
The Pro…

#hackernews #news
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain
Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585 that has been observed delivering an off-the-shelf malware called MonsterV2 via phishing campaigns. The Proofpoint Threat Research Team described the threat activity cluster as sophisticated, leveraging web injections and filtering checks as part of its attack chains. "TA585 is notable because it
thehackernews.com
October 15, 2025 at 1:24 AM
🚨 New MonsterV2 update spotted.
Key notes from dev:
🔓 Experimental app-bound decryption for Chromium browsers (no admin) now working.
🧩 Cookie decryption bugs fixed.
🛠️ Panel optimizations + cache clear/restart feature.
#ThreatIntel #Infostealer #infosec
September 22, 2025 at 8:54 AM
🚨 New update spotted in MonsterV2 malware:
✅ Stealer can now be launched on all or selected bots
⚙️ Loader speed improved
🐞 Bug fix for browser cookie theft on high-handle systems
📌 Rebuild required – expect fresh variants in the wild
#ThreatIntel #Malware #HVNC #Infostealer
July 12, 2025 at 7:15 PM
🚨 Threat Intel Alert: #monsterv2 info-stealer just received a new update.
#CyberSecurity #ThreatIntel
April 26, 2025 at 8:21 AM
🚨 Threat Intel Alert: #monsterv2 info-stealer is actively maintained and just received a new update. If you're tracking stealers, now's the time to revisit your IOCs. #CyberSecurity #ThreatIntel
April 16, 2025 at 7:53 AM
MonsterV2 #stealer
March 15, 2025 at 1:51 PM
IRS phishing → MonsterV2 HVNC squatting inside your clipboard, swapping wallets faster than you can file. TA585 built the whole crime-stack in-house; Fed fakes, GitHub ghosts, CIS no-fly. Your OS is now a rented mule—evict or pay 2k/mo. 🕳️
Researchers Expose TA585's MonsterV2 Malware Capabilities and Attack Chain
Researchers link TA585 to MonsterV2 RAT stealer delivered via IRS-themed phishing, JavaScript injects, and GitHub lures.
thehackernews.com
October 14, 2025 at 8:17 PM
Cybersecurity alert: Researchers uncover TA585's MonsterV2 malware, a sophisticated threat with full attack chain control. Stay vigilant! #CyberSecurity #Malware #TA585 #MonsterV2 Link: thedailytechfeed.com/unveiling-ta...
October 15, 2025 at 7:19 AM
Cybercriminal group TA585 employs unique web injection techniques to deliver MonsterV2 malware, targeting Windows systems. Stay vigilant! #CyberSecurity #Malware #TA585 #MonsterV2 Link: thedailytechfeed.com/ta585s-innov...
October 15, 2025 at 6:50 AM
Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain https://thehackernews.com/2025/10/researchers-expose-ta585s-monsterv2.html
October 14, 2025 at 7:47 AM