All IOCs associated with Cipher Tech blog posts can be found at https://github.com/ciphertechsolutions/acce_iocs.
Continue readingACCE Release Notes v2.9.20250602
This release consists of the following: Armillaria Loader In early May a sample was uploaded to VirusTotal which was detected as BumbleBee malware. Analysis of the sample indicates it is a new loader, which we are calling Armillaria, that was observed loading BumbleBee, ChuChuka Implant, Lumma Stealer, Stealc Stealer, WHT Downloader, and some of threat researcher Hasherezade’s open-source tools. Armillaria employs anti-analysis techniques including the use of junk code to inflate the size of the entry function, which was observed to prevent a decompiler from analyzing the function. The loader also dynamically resolves APIs using a custom add-polynomial hashing algorithm, where: As part of the loading sequence: The initial payload is a Donut shellcode variant which uses Halo’s Gate to check if Windows API’s are hooked and has differences in the configuration structure when compared to the base repository and it’s various versions. Samples: ChuChuka Implant One of the Armillaria payloads is an implant we are calling ChuChuka based upon a consistent screenshot directory observed in the five (5) samples we observed. ChuChuka has keylogger, screenshot, and stealer capabilities (targeting browsers, Coinomi, Exodus, and Electrum). Network communications are RC4 encrypted, and in response to the initial packet the server is expected to return the RC4 key to complete the handshake. C2 commands were observed to contain at least the following: […]
Continue readingACCE Release Notes v2.9.20250508
The May 2025 release notes highlight updates to rutserv and MonsterCrypt / Aurotun among other stealers and ransomware.
Continue readingACCE Release Notes v2.9.20250421
This release consists of updates for AutoColor, Crystal Stealer, ExosStealer, Lumma, VenomRAT and more.
Continue readingACCE Release Notes v2.9.20250320
Latest releases for Prysmax, AutocRAT, DBatLoader, Onimai and more.
Continue readingACCE Release Notes v2.8.20250211
This month’s release features expanded updates for Going Crypter, Jason Stealer, C4 Crypter and more.
Continue readingACCE Release Notes v2.8.20250115
Our first release of 2025 includes uupdates for HeartCrypt, PumaKit, StarCat, PeakLight and CStealer.
Continue readingACCE Release Notes v2.8.20241223
Updates for Waltuhium-based malware, Cocorico Stealer, ElizaRAT and more.
Continue readingACCE Release Notes v2.8.20241126
This update version includes details on MjrMnr Implant, Cake Malware, HijackLoader RGB+XOR and more.
Continue readingACCE Release Notes v2.8.20241104
This edition of release notes consists of updates for Crystal Stealer, JPHP Compiled Archives, DarkCrystalRAT, and many more.
Continue readingACCE Release Notes v2.7.20241009
This October releases includes numerous Malware additions as well as emphasis on Poseidon Loader and Amnesia Stealer.
Continue reading