After collab w/ @intel471.bsky.social, @malwareindepth.com & others, we believe this malware is actually MonsterV2, a newer version of an existing infostealer.
After collab w/ @intel471.bsky.social, @malwareindepth.com & others, we believe this malware is actually MonsterV2, a newer version of an existing infostealer.
666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e
b869941a9c476585bbb8f48f7003d158c71e44038ceb2628cedb231493847775
Signatures:
ET sig: 2061200 - ET MALWARE MonsterV2 Stealer CnC Checkin
666944b19c707afaa05453909d395f979a267b28ff43d90d143cd36f6b74b53e
b869941a9c476585bbb8f48f7003d158c71e44038ceb2628cedb231493847775
Signatures:
ET sig: 2061200 - ET MALWARE MonsterV2 Stealer CnC Checkin
In addition, some samples of MonsterV2 check to see if the target resides in a CIS country (RU;BY;UA;KZ;UZ;TM;KG;AM;TJ;MD;LV;LT;EE).
It checks this to prevent infection of targets in these countries.
In addition, some samples of MonsterV2 check to see if the target resides in a CIS country (RU;BY;UA;KZ;UZ;TM;KG;AM;TJ;MD;LV;LT;EE).
It checks this to prevent infection of targets in these countries.
[+] Cookie export in JSON via stealer panel
[=] Lib updates (panel + daemon)
[=] Error message fixes
#infosec #malware #threatintel
[+] Cookie export in JSON via stealer panel
[=] Lib updates (panel + daemon)
[=] Error message fixes
#infosec #malware #threatintel
Introduction In 2025, cybersecurity researchers have identified a new threat actor, TA585, whose operations are redefining the landscape of cybercrime. Unlike traditional malware groups that rely heavily on third-party services,…
Introduction In 2025, cybersecurity researchers have identified a new threat actor, TA585, whose operations are redefining the landscape of cybercrime. Unlike traditional malware groups that rely heavily on third-party services,…
Reported Date: 07/17/2025
PDF URL: https://www.cyber.nj.gov/Home/Components/News/News/1753/214
Title: ClickFix Leading to MonsterV2 Infostealer
Reported Date: 07/17/2025
PDF URL: https://www.cyber.nj.gov/Home/Components/News/News/1753/214
Title: ClickFix Leading to MonsterV2 Infostealer
Learn more: https://loom.ly/WgL-664
Learn more: https://loom.ly/WgL-664
📝 Selon Infosecurity Magazine, un **nouveau groupe cybercriminel** baptisé **TA585** a été ide…
https://cyberveille.ch/posts/2025-10-16-le-groupe-ta585-diffuse-le-malware-monsterv2-dans-une-operation-avancee/ #IOC #Cyberveille
📝 Selon Infosecurity Magazine, un **nouveau groupe cybercriminel** baptisé **TA585** a été ide…
https://cyberveille.ch/posts/2025-10-16-le-groupe-ta585-diffuse-le-malware-monsterv2-dans-une-operation-avancee/ #IOC #Cyberveille
Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585 that has been observed delivering an off-the-shelf malware called MonsterV2 via phishing campaigns.
The Pro…
#hackernews #news
Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585 that has been observed delivering an off-the-shelf malware called MonsterV2 via phishing campaigns.
The Pro…
#hackernews #news
Key notes from dev:
🔓 Experimental app-bound decryption for Chromium browsers (no admin) now working.
🧩 Cookie decryption bugs fixed.
🛠️ Panel optimizations + cache clear/restart feature.
#ThreatIntel #Infostealer #infosec
Key notes from dev:
🔓 Experimental app-bound decryption for Chromium browsers (no admin) now working.
🧩 Cookie decryption bugs fixed.
🛠️ Panel optimizations + cache clear/restart feature.
#ThreatIntel #Infostealer #infosec
✅ Stealer can now be launched on all or selected bots
⚙️ Loader speed improved
🐞 Bug fix for browser cookie theft on high-handle systems
📌 Rebuild required – expect fresh variants in the wild
#ThreatIntel #Malware #HVNC #Infostealer
✅ Stealer can now be launched on all or selected bots
⚙️ Loader speed improved
🐞 Bug fix for browser cookie theft on high-handle systems
📌 Rebuild required – expect fresh variants in the wild
#ThreatIntel #Malware #HVNC #Infostealer
#CyberSecurity #ThreatIntel
#CyberSecurity #ThreatIntel