My Account Login

ANY.RUN Exposes Pentagon Stealer: Crypto and Data Theft Malware Targeting Businesses

DUBAI, DUBAI, UNITED ARAB EMIRATES, April 29, 2025 /EINPresswire.com/ -- ANY.RUN, a premier provider of interactive malware analysis and threat intelligence solutions, has published a comprehensive report by its analyst team exposing Pentagon Stealer, an evolving malware that poses a critical threat to organizations worldwide.

๐๐ž๐ง๐ญ๐š๐ ๐จ๐ง ๐’๐ญ๐ž๐š๐ฅ๐ž๐ซ: ๐Š๐ž๐ฒ ๐“๐ก๐ซ๐ž๐š๐ญ๐ฌ

Pentagon Stealer, in Python and Golang variants, steals sensitive data with advanced techniques:

ยท ๐——๐—ฎ๐˜๐—ฎ ๐—ง๐—ต๐—ฒ๐—ณ๐˜: Extracts browser credentials, cookies, Atomic/Exodus wallet data, Discord/Telegram tokens, and files from Chromium- and Gecko-based browsers (Firefox, Zen, Waterfox).

ยท ๐— ๐˜‚๐—น๐˜๐—ถ๐—ฝ๐—น๐—ฒ ๐—ฉ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ป๐˜€: The malware is extensively utilized under different names 1312, Acab, Vilsa, and BLX stealer.

ยท ๐—–๐—ฟ๐˜†๐—ฝ๐˜๐—ผ ๐—ช๐—ฎ๐—น๐—น๐—ฒ๐˜ ๐—œ๐—ป๐—ท๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป: Replaces app.asar files in Atomic/Exodus wallets to steal mnemonics/passwords.

ยท ๐——๐—ฒ๐—ฏ๐˜‚๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ: Launches Chromium browsers in debug mode to bypass DPAPI encryption, stealing unencrypted cookies.

ยท ๐—–๐Ÿฎ ๐—–๐—ผ๐—บ๐—บ๐˜‚๐—ป๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป: Uses HTTP with pentagon[.]cy/stealer[.]cy servers; BLX uploads to gofile.io, sending links to C2.

Its evolution and integration into attack chains with droppers/miners amplify its risk.

Read the analysis on ANY.RUNโ€™s blog.

๐‡๐จ๐ฐ ๐€๐๐˜.๐‘๐”๐ ๐‡๐ž๐ฅ๐ฉ๐ฌ ๐๐ฎ๐ฌ๐ข๐ง๐ž๐ฌ๐ฌ๐ž๐ฌ ๐‚๐จ๐ฎ๐ง๐ญ๐ž๐ซ ๐๐ž๐ง๐ญ๐š๐ ๐จ๐ง ๐’๐ญ๐ž๐š๐ฅ๐ž๐ซ ๐€๐ญ๐ญ๐š๐œ๐ค๐ฌ

ANY.RUNโ€™s Interactive Sandbox provides companies and SOC teams with the ability to detect and analyze Pentagon Stealer attacks.

Businesses can leverage its real-time insights to extract Indicators of Compromise (IOCs), monitor C2 communications, and trace infection chains, enabling fast detection and mitigation.

๐€๐›๐จ๐ฎ๐ญ ๐€๐๐˜.๐‘๐”๐

ANY.RUN is a trusted partner for over 15,000 organizations in finance, healthcare, retail, technology, and beyond, delivering advanced malware analysis and threat intelligence products. Its cloud-based Interactive Sandbox, Threat Intelligence Lookup, and TI Feeds enable businesses to detect, analyze, and investigate the latest malware and phishing campaigns to streamline triage, response, and proactive security.

The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn

Twitter

View full experience

Distribution channels: Banking, Finance & Investment Industry, IT Industry, International Organizations, Technology, World & Regional