{"id":99587,"date":"2025-04-13T07:17:17","date_gmt":"2025-04-13T07:17:17","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=99587"},"modified":"2025-04-13T07:17:20","modified_gmt":"2025-04-13T07:17:20","slug":"trox-stealer-exfiltrate-sensitive-data","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/","title":{"rendered":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials"},"content":{"rendered":"\n<p>A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security, leveraging psychological manipulation and technical sophistication to exfiltrate sensitive information.<\/p>\n\n\n\n<p>First observed in December 2024 by Sublime Security analysts, this Malware-as-a-Service (MaaS) product targets stored credit card details, browser credentials, cryptocurrency wallets, and session files for platforms like Discord and Telegram.<\/p>\n\n\n\n<p>The malware operates on a weekly subscription model, enabling rapid deployment of short-lived campaigns that prioritize volume over persistence.<\/p>\n\n\n\n<p>TROX Stealer distinguishes itself through its exploitation of urgency-based social engineering.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjlr5obCiR51DqWuepAaQTmstsaw9yQakNpbec6PVfm5qZVpIzGJLx0buCcXXulVYS3y1xHo-vuhuSZAEkPx1MY0wh1aRrSnKDoBhWpmx_dlyhnTEVzQ7cpWape1jWrFhhuLxvAe-SxFa3nqsZBbGGym8ItIPEAAa3c_-veJwevga3e_UJSLz2I9UZt_HQ\/s16000\/DEBT%20COLLECTION%20COURT%20DOCUMENTS%20(Source%20-%20Sublime%20Security).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">DEBT COLLECTION COURT DOCUMENTS (Source &#8211; Sublime Security)<\/figcaption><\/figure><\/div>\n\n\n<p>Attackers deliver payloads via emails disguised as debt collection notices or legal threats, capitalizing on victims\u2019 anxiety to bypass scrutiny.<\/p>\n\n\n\n<p>These messages, often generated using large language models (LLMs), direct recipients to spoofed domains hosting malicious executables.<\/p>\n\n\n\n<p>The payloads employ multi-layered obfuscation techniques, including Python-to-native binary compilation and WebAssembly (Wasm) smuggling, to evade detection.<\/p>\n\n\n\n<p>Sublime Security researchers <a href=\"https:\/\/sublime.security\/blog\/trox-stealer-a-deep-dive-into-a-new-malware-as-a-service-maas-attack-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the malware\u2019s infrastructure reveals a methodical approach to operational security.<\/p>\n\n\n\n<p>Attack domains such as <code>documents[.]debt-collection-experts[.]com<\/code> use tokenized download links to prevent re-infection and complicate analysis.<\/p>\n\n\n\n<p>The campaign\u2019s backbone relies on IP addresses like <code>89.185.82.34<\/code>\u2014a suspected Tor exit node\u2014and Cloudflare-protected servers, illustrating the authors\u2019 investment in anonymization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism: From Social Engineering to Silent Execution<\/strong><\/h2>\n\n\n\n<p>The infection chain begins with a carefully crafted email urging immediate action to avoid legal consequences.<\/p>\n\n\n\n<p>A typical subject line, \u201cFinal Warning: Legal Action Pending for Your Account,\u201d directs victims to a link labeled &#8220;DEBT COLLECTION COURT DOCUMENTS.&#8221;<\/p>\n\n\n\n<p>Clicking this link triggers a download of an executable file named <code>DebtCollectionCase#######.exe<\/code>, where the placeholder represents a unique seven-digit identifier.<\/p>\n\n\n\n<p>The downloaded executable, compiled using Nuitka to convert <a href=\"https:\/\/cybersecuritynews.com\/malicious-python-packages-attacking-popular-cryptocurrency-library\/\" target=\"_blank\" rel=\"noreferrer noopener\">Python scripts<\/a> into native binaries, extracts components to a temporary directory (<code>%Temp%\\onefile_11536_133873237425638862<\/code>).<\/p>\n\n\n\n<p>These components include:-<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A decoy PDF (e.g., <code>client_pdf_case_388.pdf<\/code>) mimicking legitimate legal documents<\/li>\n\n\n\n<li>A Node.JS interpreter (<code>node700.exe<\/code>) embedding malicious JavaScript<\/li>\n\n\n\n<li>Support libraries like <code>libcrypto-3.dll<\/code> and <code>python312.dll<\/code><\/li>\n<\/ul>\n\n\n\n<p>The Python script orchestrates file execution, as revealed by internal documentation extracted during analysis:-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code> \n```python  \ndef install_files(user_profile, target_dir, source_dir, exe_pattern, pdf_pattern):  \n    # Copies 'node*.exe' and PDFs to AppData  \n    ...  \ndef run_files(user_profile, target_dir, exe_pattern, pdf_pattern):  \n    # Executes the Node.JS binary and opens the decoy PDF  \n    ...  \n```<\/code><\/pre>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgkC6HqCD3Ec_UXnHzFdGPTlitNBcrKNIkYLyu1CMBjFlQfVYzC_ocHl_7zIFB7_hesx_L7U_vaDauDs1xESmSIUhSTHnjpncYMYk11LSjrWUmy7Q8l8VeOpuNmVHqwe_i1vh3wTB8u0ZJmNeXhsDLCWTafIyG1QQE7atMwsN3OlAlTrlycP5aIA7EFBBc\/s16000\/Decoy%20PDF%20(Source%20-%20Sublime%20Security).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">Decoy PDF (Source &#8211; Sublime Security)<\/figcaption><\/figure><\/div>\n\n\n<p>The decoy PDF contains metadata artifacts such as <code>Modified: Copy\\040388<\/code>, a signature of automated generation via PyPDF2.<\/p>\n\n\n\n<p>Meanwhile, the Node.JS binary executes a Base64-encoded WebAssembly module, enabling Rust-compiled <a href=\"https:\/\/cybersecuritynews.com\/fin7-hackers-sponsored-google-ads-msix-payloads\/\" target=\"_blank\" rel=\"noreferrer noopener\">payloads<\/a> to run in memory:-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>```javascript  \nvar bytes = Buffer2.from(\"AGFzbQEAAAABvwRHYAJ\/fwBgAX8AYAJ\/fwF\/YAN\/f38Bf2ADf39\/A...\");  \nvar wasmModule = new WebAssembly.Module(bytes);  \nvar wasmInstance = new WebAssembly.Instance(wasmModule, imports);  \n```<\/code><\/pre>\n\n\n\n<p>This 2MB Wasm blob contains over 4,700 functions, many interacting with system APIs to harvest data.<\/p>\n\n\n\n<p>Upon execution, the malware transmits a <a href=\"https:\/\/cybersecuritynews.com\/python-json-logger-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">JSON<\/a> profile of the victim\u2019s system to <code>172.22.117.177:2777<\/code>, including hardware specs and OS details:-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>```json  \n{  \n  \"username\": \"admin\",  \n  \"osType\": \"Windows_NT\",  \n  \"cpuModel\": \"Intel(R) Core(TM) i5-6400\",  \n  \"totalMemoryGB\": \"3.99\"  \n}  \n```<\/code><\/pre>\n\n\n\n<p>The IP, registered to \u201cSTARK INDUSTRIES SOLUTIONS LTD.\u201d in London, resolves to a server hosting additional payloads (<code>*.json<\/code> and <code>*.js<\/code> files), suggesting dynamic C2 capabilities.<\/p>\n\n\n\n<p>TROX Stealer\u2019s use of urgency-themed lures and rapidly shifting infrastructure complicates traditional IOC-based detection.<\/p>\n\n\n\n<p>Defenders should prioritize behavioral <a href=\"https:\/\/cybersecuritynews.com\/best-remote-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring<\/a> for processes like <code>node*.exe<\/code> spawning from temporary directories and outbound connections to high-risk IPs.<\/p>\n\n\n\n<p>The malware\u2019s reliance on Wasm and LLM-generated decoys underscores the need for advanced email security solutions capable of intercepting socially engineered threats before they reach end-users.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Find this News Interesting! Follow us on&nbsp;<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,&nbsp;<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, &amp;&nbsp;<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>&nbsp;to Get Instant Updates!<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Also Read:<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-wp-embed is-provider-cyber-security-news wp-block-embed-cyber-security-news\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"baJY2WcOLS\"><a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-10-ics-advisories\/\">CISA Releases 10 ICS Advisories Covering Vulnerabilities &#038; Exploits<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8220;CISA Releases 10 ICS Advisories Covering Vulnerabilities &#038; Exploits&#8221; &#8212; Cyber Security News\" src=\"https:\/\/cybersecuritynews.com\/cisa-releases-10-ics-advisories\/embed\/#?secret=SUOsD4PGHM#?secret=baJY2WcOLS\" data-secret=\"baJY2WcOLS\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security, leveraging psychological manipulation and technical sophistication to exfiltrate sensitive information. First observed in December 2024 by Sublime Security analysts, this Malware-as-a-Service (MaaS) product targets stored credit card details, browser credentials, cryptocurrency wallets, and session files for [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":99605,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-99587","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials<\/title>\n<meta name=\"description\" content=\"A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials\" \/>\n<meta property=\"og:description\" content=\"A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-13T07:17:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-13T07:17:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards & Browser Credentials","description":"A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/","og_locale":"en_US","og_type":"article","og_title":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials","og_description":"A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security.","og_url":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-04-13T07:17:17+00:00","article_modified_time":"2025-04-13T07:17:20+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials","datePublished":"2025-04-13T07:17:17+00:00","dateModified":"2025-04-13T07:17:20+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/"},"wordCount":525,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/","url":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/","name":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards & Browser Credentials","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-04-13T07:17:17+00:00","dateModified":"2025-04-13T07:17:20+00:00","description":"A newly identified malware strain known as TROX Stealer has emerged as a significant threat to consumer data security.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#primaryimage","url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/trox-stealer-exfiltrate-sensitive-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"TROX Stealer Exfiltrate Sensitive Data Including Stored Credit Cards &amp; Browser Credentials"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik-B-h5ixiqgEWRdsh1jgFNvf88L4DnTfAhOLMRehs1Lsr2YIZWE3nF3FyEJM1F-ZipWvT79bN6mPLYC0FrVuyAq8673wjCVK7ayJ1wnpJQZTSE0MjSrdwNAqymzaEEj7McTkXFVkcY5u5GOQPKlWDfSpdLZnBAOvXe2J-V8AcQRlFPNLmqMQb7Rst87w\/s16000\/TROX%20Stealer%20Exfiltrate%20Sensitive%20Data%20Including%20Stored%20Credit%20Cards%20&%20Browser%20Credentials.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/99587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=99587"}],"version-history":[{"count":3,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/99587\/revisions"}],"predecessor-version":[{"id":99604,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/99587\/revisions\/99604"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/99605"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=99587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=99587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=99587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}