File: Hdx-home-beta-windows.zip ... -
Targets browser extensions like MetaMask or desktop wallets (e.g., Atomic, Exodus).
Upon extraction and execution of the contents within the ZIP file, the following stages typically occur: File: hdx-home-beta-windows.zip ...
Shared in communities interested in beta testing or gaming performance boosts. 4. Technical Analysis & Behavior Targets browser extensions like MetaMask or desktop wallets
It checks for the presence of debuggers, sandboxes, or virtual machines (VMs). If detected, it may terminate to avoid analysis. B. Data Harvesting (Infostealing) The malware scans the local system for: Technical Analysis & Behavior It checks for the
Steals saved passwords, auto-fill data, and credit card info from Google Chrome , Microsoft Edge , and Mozilla Firefox .
The malware connects to a remote server (C2) to upload the stolen data. These servers are often hosted on obfuscated IP addresses or use Telegram bots as a backend for data exfiltration. If you are investigating a machine for this file, look for:
