We identified a new malware called
#HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam ๐ง, first observed on August 1, 2026 ๐ญ๐
Key Capabilities โคต๏ธ
๐ต๏ธ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners ๐ธ
๐ Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) ๐ฎ
๐ค AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session cookies ๐ช
๐ฐ Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet ๐
Artifacts observed โคต๏ธ
1๏ธโฃ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log
2๏ธโฃ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication
HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed โคต๏ธ
๐ก 31.40.204.178:7080 WhiteLabel ๐น๐ท
๐ก 94.26.3.211:7443 Stellar Group SAS ๐ซ๐ท
๐ก 192.109.139.91:7443 Stellar Group SAS ๐บ๐ธ
๐ก 195.177.94.60:7443 Stellar Group SAS ๐ซ๐ท
๐ก 107.175.148.122:7443 HostPapa ๐บ๐ธ
๐ก 209.54.103.173:7443 HostPapa ๐บ๐ธ
๐ก 132.243.225.173:7080 QWINS-Hosting ๐ฉ๐ช
๐ก 78.40.209.113:7081 QWINS-Hosting ๐ซ๐ฎ
๐ก 31.77.138.55:5654 QWINS-Hosting ๐ซ๐ฎ
๐ฆ Releated IOCs on ThreatFox:
threatfox.abuse.ch/browse/taโฆ
๐ Releated malware samples on MalwareBazaar:
bazaar.abuse.ch/browse/signaโฆ
ALT HypeAgent botnet C2 communication observed during tria.ge sandbox run