SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_122 (Back to overview)

Unidentified 122 (Stealer)


According to Datadog, this malware functions primarily as a credential and infostealer. It enumerates LevelDB files within application data directories for Discord, Chromium-based browsers, cryptocurrency wallets, and Electron applications.

References
2025-05-21DatadogAndy Giron, Eslam Salem, Ian Kretz, Tesnim Hamdouni
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions
Unidentified 122 (Stealer)

There is no Yara-Signature yet.