Date: 09/16/2026
Severity: High
Summary
HypeAgent is a multi-stage infostealer that uses JavaScript, PowerShell, .NET loaders, and PNG steganography to evade detection. It combines scheduled-task persistence, encrypted payloads, reflective loading, AMSI bypassing, and process hollowing to execute its payload. The final stealer targets browser credentials, email accounts, cryptocurrency wallets, and AI service sessions. Its ability to steal AI authentication cookies highlights the growing risk of AI account hijacking, while its embedded configuration supports WebSocket-based C2 communication.
Indicators of Compromise (IOC) List
Domain/URLs | https://files.catbox.moe/knujwn.png |
IP Address | 209.54.103.173 |
Hash | 3878923A2E0B1FDB16A307D4ACB132C2
406be1fd0f04e621aed5e0f672639b2c
75298E19A56904144133567C0911CB1E
B30C530239DCD92186D75EE30A682B10
D5868901602CF1A008592F1A6C6FE544
EFB9559AF2BDBA23245B1B51CF2EF4DF
b2837468fc05666447868fc58c66bcf0
d4c8277e209000b3066b81bb4c065fa5
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://files.catbox.moe/knujwn.png" or url like "https://files.catbox.moe/knujwn.png" or siteurl like "https://files.catbox.moe/knujwn.png" |
Detection Query 2 : | dstipaddress IN ("209.54.103.173") or srcipaddress IN ("209.54.103.173") |
Detection Query 3 : | md5hash IN ("B30C530239DCD92186D75EE30A682B10","EFB9559AF2BDBA23245B1B51CF2EF4DF","d4c8277e209000b3066b81bb4c065fa5","b2837468fc05666447868fc58c66bcf0","D5868901602CF1A008592F1A6C6FE544","406be1fd0f04e621aed5e0f672639b2c","75298E19A56904144133567C0911CB1E","3878923A2E0B1FDB16A307D4ACB132C2")
|
Reference:
https://gurucul.com/blog/hypeagent-stealer-multi-stage-infostealer-hijacking-claude-chatgpt-and-cursor-sessions/