注册并分享邀请链接,可获得视频播放与邀请奖励。

SlowMist (@SlowMist_Team) “🚨 Threat Intelligence | The StealC Info-Stealing Chain Behind the Qwen Imperson” — TopicDigg

SlowMist 的个人资料封面
SlowMist 的头像
SlowMist
@SlowMist_Team
加入 April 2018
0 正在关注    0 粉丝
🚨 Threat Intelligence | The StealC Info-Stealing Chain Behind the Qwen Impersonation Repository SlowMist Security Team identified a #GitHub# repository impersonating local quantized weights for Qwen 3.8 27B. A real Q4_K_M 27B package should exceed 16 GB. The asset delivered was only 487 KB — no GGUF weights, just three files: Application.cmd, a renamed LuaJIT interpreter, and an obfuscated Lua script disguised as cert.txt. The official #Qwen# project was not compromised. The repo kept the look of a normal offline model project, while the malicious ZIP sat in assets/. After deobfuscation, the script collects host data, takes a screenshot, and POSTs them to C2. When the hardcoded server fails, it reads a fallback C2 from a Polygon contract via eth_call, so operators can rotate infrastructure with a single on-chain transaction. Preserved C2 responses then delivered an inner payload we attribute to #StealC#, targeting: 🔹 Browser logins, cookies, and history — including a Chrome App-Bound Encryption bypass 🔹 Email, WinSCP, and Steam credentials 🔹 Wallet-related files and extension data, dispatched by server-side tasks MistEye reconstructed the multi-stage chain and compared 29 similar ZIPs across 23 repositories using the same Lua delivery stack. Between two collection dates, repositories, filenames, the outer PE, and the AES key had already rotated. A 27B model that downloads in 487 KB is not a model. Inspect asset size and unpack downloaded packages before running them. Read the full analysis 👇
显示更多