MALICIOUS (1) campaign cataloged at 2026-08-10(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-08-bigtime¶
The package contains hidden code to overwrite the built-in "open" function and exfiltrate every write to opened files. Exfiltration watcher is also attached to other files in user's home directory.
Abuse categories¶
files_exfiltration
Campaign uses files_exfiltration.