Malware

Updated Xillen Stealer expands targeting, bolsters stealth

Privacy concept: pixelated words Malware on digital background, 3d render

More environments could be covertly targeted by versions 4 and 5 of the Python-based XillenStealer malware, which has been strengthened to become an extensive data harvesting platform, reports GBHackers News.

Updated iterations of XillenStealer enabled not only the exfiltration of password manager credentials, social media accounts, and stored data across over 100 web browsers but also theft of cryptocurrency across over 70 wallets on top of targeting Internet of Things devices, Docker instances, and Kubernetes configurations, findings from a Darktrace analysis revealed.

Multiple functions allow XillenStealer to pilfer IDE configuration data, cloud credentials, SSH and API keys, biometric configuration data, enterprise credentials, time-based one-time passwords, and Azure Active Directory and Kerberos single sign-on tokens.

Moreover, XillenStealer, which also uses artificial intelligence for target discovery, has also been integrated with the new AIEvasionEngine module that copies user and system behavior to circumvent AI-based and behavior-based detection tools, according to researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds