ericWadeFord

0 Followers
0 Following
3 Posts
Threat Intelligence Analyst at Deepwatch

#InformationStealer Discovered Capable of Stealing RDP Files

Source: https://blog.cyble.com/2023/02/01/vector-stealer-a-gateway-for-rdp-hijacking/

Cyble observed an information-stealing #malware capable of stealing .rdp files, passwords, and cookies. #Cybercriminals can exfiltrate sensitive information from the victim's machine using SMTP, Discord, and Telegram. With the capability to steal RDP files, cybercriminals can use the stolen files to perform RDP hijacking, enabling them to gain unauthorized remote access without credentials. The stealer surfaced in cybercrime forums in the second half of 2022 and is sold through publicly available platforms.

#CTI #threatintel

Vector Stealer: A Gateway for RDP Hijacking

Cyble Research & Intelligence Labs analyses VectorStealer, capable of stealing RDP files with possible ties to KGB Crypter.

Cyble