Trusted Design

Threat Snapshot: Djinn Stealer

概要

Djinn Stealer is a cross-platform information stealer delivered as a second-stage payload by the TaskWeaver Node.js loader. It employs a rules-based collection engine to harvest credentials and configuration data from cloud platforms, source control systems, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets. The stolen data is archived, encrypted, and exfiltrated to attacker-controlled infrastructure. This threat has been observed following exploitation of the SimpleHelp vulnerability CVE-2026-48558. The stealer executes within a Node.js runtime context and communicates with command-and-control servers using encrypted channels for data exfiltration.

Created: 2026-09-10

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る