VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

2026-05-14 Hybrid Analysis

https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html

Thumbnail for VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

Hybrid Analysis identified a VELVET CHOLLIMA-assessed infostealer operation distributing a signed Windows MSI that masquerades as the Tralert FX cryptocurrency trading application. The installer exposed live credentials and GitLab access tokens, revealing a multi-stage loader chain that uses GitLab repositories for payload delivery, scheduled-task persistence, and recurring exfiltration. The malware collects host reconnaissance, keylogs, and Chromium browser credentials, then pushes stolen data into GitLab repositories every 30 minutes for human triage of cryptocurrency-focused victims. The final payload is MoonPeak, a custom XenoRAT variant, with infrastructure including Tralert/Talert lure domains, GitLab projects, C2 hosts, mutexes, hashes, and the hardcoded C2 IP 91.107.246.107. The campaign matters because the exposed repositories showed active compromise, more than 4,100 commits, roughly 90 affected hosts, and an operational focus on crypto account takeover.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
EMAIL [email protected] 2026-05-14 2026-05-14
URL https://github.com/Fujinuma0804… 2026-05-14 2026-05-14
URL https://github.com/vergiegpham/… 2026-05-14 2026-05-14
URL http://161.97.113.34:3001/api/t… 2026-05-14 2026-05-14
DOMAIN endava.online 2026-05-14 2026-05-14
DOMAIN talert.space 2026-05-14 2026-05-14
DOMAIN talert.online 2026-05-14 2026-05-14
DOMAIN talert.store 2026-05-14 2026-05-14
DOMAIN talert.site 2026-05-14 2026-05-14
DOMAIN tralert.store 2026-05-14 2026-05-14
DOMAIN tralert.site 2026-05-14 2026-05-14
DOMAIN trumpalert.store 2026-05-14 2026-05-14
DOMAIN tralert7.com 2026-05-14 2026-05-14
DOMAIN tralert.online 2026-05-14 2026-05-14
IPv4 91.107.246.107 2026-05-14 2026-05-14
IPv4 161.97.113.34 2026-05-14 2026-05-14
HASH 3c356065e32ac8cbc6ec330581c7c34… 2026-05-14 2026-05-14
HASH eaba341f94e700ff470e7a8fb3fe596… 2026-05-14 2026-05-14
HASH 528b004407d32bbc6299540a7a9fd98… 2026-05-14 2026-05-14
HASH 384255ba8bea8997dce5a6a9c4b4352… 2026-05-14 2026-05-14

Related Actors

Related Reports

2026-04-17 • 33% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Phishing, T1056.001, T1053.005 • Published within a month
« Back