CYFIRMA Research

CYFIRMA Research- Hannibal Stealer: A Rebranded Threat Born from Sharp and TX Lineage

CYFIRMA

Read CYFIRMA’s report on the Hannibal Stealer, a rebranded variant of SHARP and TX Stealers, which has re-emerged with expanded data exfiltration capabilities and an updated command-and-control infrastructure. Hannibal Stealer is built in C# on the .NET framework. It targets a wide range of data sources, including browsers, cryptocurrency wallets, VPN configurations, FTP credentials, and system information. It incorporates clipboard hijacking and geofencing techniques to maximize impact. The malware is managed through a Django-based control panel, enabling real-time log monitoring and payload distribution. Current promotion across Telegram and underground forums points to sustained activity.

Link to the Research Report: https://www.cyfirma.com/research/hannibal-stealer-a-rebranded-threat-born-from-sharp-and-tx-lineage/
 
 #CyberThreat #HannibalStealer #InfoStealer #ThreatIntel #MalwareAnalysis #C2Infrastructure #Cybersecurity #CYFIRMA #CyfirmaResearch #ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/