NEWS Passwords, cookies, sessions of Telegram and greeted phrases. Talk about a new platform for criminals Needle

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,588
A file of only 11 kilobytes in size hid the most powerful platform for total hacking.
1777359815018.png
Ordinary in the form downloader Phorpiexпривёл specialists of Breakglass Intelligence to a much larger find. Behind an inconspicuous file of only 11 KB, the infrastructure was hidden, where the theft of cryptocurrency, the mining of Monero and the sending of letters for extortion at the same time worked.

The sample 8j5bsr.exe hit MalwareBazaar on April 20, 2026. Inside, the specialists found seven rigidly given links to the server 178.16.54.[] 109. The downloader downloaded executable files in a Windows time folder, ran them and left the infection marker. At first glance, the scheme resembled the ordinary activity of Phorpiex, but the server quickly issued a full set of modules of the new criminal Needle platform.

According to Breakglass Intelligence, the operator deleted the files about eight minutes after the first access, but the team managed to get all seven useful loads. Among them were the XMRig installer, the miner himself, the peinf.exe file collector, the Phorpiex distribution module and several components for spam campaigns. In peinf.exe found the line TWIZTPEPINF, which indicates the pseudonym of the operator TWIZT.

Needle turned out to be a full-fledged crimeware-as-a-service platform. The panel worked on React, supported several languages, used Bearer toys to access and allowed to create its own builds of malicious modules. The set included a password stalk, cookies, bank card data, autocomplete, tokens, browser history, FTP-accounting data, Telegram sessions and wallet files. Also, the platform was able to take screenshots, intercept forms and replace crypto addresses in the clipboard.

The main module of Needle experts called the substitution of browser crypto wallets. The platform was targeted at Meta Mask, Phantom, Trust Wallet, Coinbase Wallet, Rabby, Keplr, OKX Wallet and Brave Wallet. The report includes support for Ethereum, BNB Chain, Polygon, Solana, Trona, Bitcoin, Litecoin, Dogecoin, Avalanche, Arbitrum, Optimism and Base. A separate module worked with table wallets Ledger, Trezor, Exodus, Atomic, Guarda, Tontier, Zelcore and Coinom, and could also save seed phrases.

On the same server worked private pool Monero on the port 6060. The miner ran under names similar to Windows system processes, limited the load to 25% of the CPU and secured through the auto-run key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Config.

The second machine, 130.12.180[.]190, served as a node for spam campaigns. There were stored packages with pairs of email and password. According to Breakglass Intelligence, only two campaigns have issued more than 120 thousand packages, which corresponds to approximately 960 million data issuance, taking into account repetitions. In the sample most often met addresses web.de and videotron.ca.

Spam modules sent letters extortion through compromised SMTP accounts. The recipients were threatened with the publication of intimate records and demanded $800 in Bitcoin. At the time of the report, the bound BTC wallet did not contain transactions, which indicates a fresh or so far unsuccessful campaign.

Such findings remind that even relatively old threats cannot be written off. Behind a familiar loader can hide a new ecosystem, where each module brings individual income to attackers, and the reaction speed of analysts becomes decisive.
 
6,260Threads
84,495Messages
6,022Members
rangesportLatest member
Top Bottom