File: Hdx-home-beta-windows.zip ... -
Collects hardware specs, IP addresses, and screenshots of the desktop.
Steals saved passwords, auto-fill data, and credit card info from Google Chrome , Microsoft Edge , and Mozilla Firefox . File: hdx-home-beta-windows.zip ...
The malware connects to a remote server (C2) to upload the stolen data. These servers are often hosted on obfuscated IP addresses or use Telegram bots as a backend for data exfiltration. If you are investigating a machine for this file, look for: Collects hardware specs, IP addresses, and screenshots of
Steals Discord tokens and Telegram session files to bypass 2FA. C. Command & Control (C2) Communication Collects hardware specs
The executable often uses a "packer" to hide its actual code from basic antivirus scans.
