CursedGrabber Malware
Summary
The latest threat of this type to be detected by infosec researchers is called xpc.js and belongs to the CursedGrabber Malware family. Lib.exe is an infostealer malware that harvests various data types from compromised systems and sends it back to the attackers through Discord webhooks. Furthermore, it establishes a backdoor with a REST API running on port 20202 on the compromised machine, ensuring easy access to the Command-and-Control infrastructure. The winresume binary is a tampered version of the legitimate winresume.exe application that facilitates the resuming of Windows computers that have been in hibernation mode for prolonged periods. The goal is to hide corrupted code into legitimate binaries making the detection of threats that much harder.