yeah it's a stealer. c2 is aleria-ggs[.]live
very extensive capabilities:
- browsers: passwords, cookies, history, bookmarks, autofills, credit cards, form history
- crypto wallets: Exodus, Electrum, Atomic, Jaxx, Coinomi, Armory, Guarda, Bitcoin-QT, Monero, Trezor Suite, Ledger Live, wallet.dat files, MetaMask, Phantom, TronLink, Binance, Coinbase, Trust, XDEFI, Ronin, ImToken, TokenPocket, Brave Wallet, and ~400 more
- messengers: Telegram (tdata directory), Discord tokens, Signal, Elements
- gaming: steam (config.vdf, loginusers.vdf, local.vdf — including decrypting stored SSFN tokens),battle•net, Epic Games, GOG Galaxy, Ubisoft (user.dat settings.yml), Origin
- ftp/vpn: FileZilla, Total Commander, NordVPN, ProtonVPN, OpenVPN, WinSCP
- 2fa: Authy, GAuth, TOTP, AdsPower, Authentiq, Nithra, EOS Authenticator 30 other 2fa apps
- system: screenshot capture, process enumeration, registry enumeration, file locking bypass, CreateRemoteThread for injection, and a ton of fingerprinting
the stealer is really smart. it manages to bypass Chrome App-Bound Encryption, AMSI, ETW, and WLDP. also has anti-sandbox and anti-vm obviously.