Artwork

Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

CYFIRMA Research: Understanding CyberEye RAT Builder- Capabilities and Implications

5:30
 
Share
 

Manage episode 489054346 series 3472819
Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

CYFIRMA’s latest research report analyses a stealthy Windows-based malware known as CyberEye, which is posing a significant threat across systems by offering attackers full remote control through a Telegram Bot API. Once executed, it silently harvests browser-stored passwords, cookies, credit card details, Wi-Fi credentials, and session tokens from apps like Telegram, Discord, and Steam. It monitors clipboard activity in real time, hijacking cryptocurrency wallet addresses to redirect funds.
The malware disables Windows Defender protections using PowerShell, evades analysis, and exfiltrates stolen data instantly via Telegram chats. It can log keystrokes, capture screenshots, record desktop activity, and steal entire folders like Minecraft profiles or desktop files. Designed to blend in with legitimate software, it can persist silently, avoid detection, and respond to attacker commands over encrypted channels.
A private Telegram channel run by the developer suggests the existence of a premium variant with extended capabilities. This malware highlights the growing sophistication of commodity threats and their increasing distribution across underground channels.
Link to the Research Report: https://www.cyfirma.com/research/understanding-cybereye-rat-builder-capabilities-and-implications/

#CyberSecurity #MalwareAlert #StaySafeOnline #CYFIRMA #CYFIRMAResearch

#ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/

  continue reading

225 episodes

Artwork
iconShare
 
Manage episode 489054346 series 3472819
Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

CYFIRMA’s latest research report analyses a stealthy Windows-based malware known as CyberEye, which is posing a significant threat across systems by offering attackers full remote control through a Telegram Bot API. Once executed, it silently harvests browser-stored passwords, cookies, credit card details, Wi-Fi credentials, and session tokens from apps like Telegram, Discord, and Steam. It monitors clipboard activity in real time, hijacking cryptocurrency wallet addresses to redirect funds.
The malware disables Windows Defender protections using PowerShell, evades analysis, and exfiltrates stolen data instantly via Telegram chats. It can log keystrokes, capture screenshots, record desktop activity, and steal entire folders like Minecraft profiles or desktop files. Designed to blend in with legitimate software, it can persist silently, avoid detection, and respond to attacker commands over encrypted channels.
A private Telegram channel run by the developer suggests the existence of a premium variant with extended capabilities. This malware highlights the growing sophistication of commodity threats and their increasing distribution across underground channels.
Link to the Research Report: https://www.cyfirma.com/research/understanding-cybereye-rat-builder-capabilities-and-implications/

#CyberSecurity #MalwareAlert #StaySafeOnline #CYFIRMA #CYFIRMAResearch

#ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/

  continue reading

225 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play