MALICIOUS (1) campaign cataloged at 2025-04-12(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2025-04-colorona¶
If the method "SetTerminalColor", imitating colorama package, is called, then the code exfiltrated browser, discord and Minecraft passwords/tokens.
Abuse categories¶
action-hidden-in-lib-usage
Campaign uses action-hidden-in-lib-usage.
exfiltration_browser_data
Campaign uses exfiltration_browser_data.
typosquatting
Campaign uses typosquatting.