#RNStealer
Malware/Tool
RN Stealer is a Python information stealer used by North Korean group Slow Pisces against cryptocurrency developers through fake coding challenges. A malicious project conditionally served a YAML deserialization payload, which installed the memory-resident RN Loader and delivered RN Stealer to validated victims. The recovered macOS-tailored script collects the username, hostname, architecture, installed applications, home-directory contents, login.keychain-db, and AWS, Kubernetes, and Google Cloud configuration files. It communicates over HTTPS, assigns a random victim ID as a cookie, obtains an XOR key, and uses Base64-encoded R0, R64, R128, and R256 tokens to request keys and mark exfiltration stages.
-
2
Tagged Reports
-
2
Unique Authors
-
263
Active Days