An updated version (V2) of the dangerous information-stealing malware Typhon Reborn has been released by its creator, with improved features to avoid detection and evade analysis.
See also: New Rorschach ransomware is the fastest encryptor discovered so far

The new version of the product is available on criminal underground for a variety of subscription options: $59 per month, an annual subscription of $360, or you can purchase a lifetime access pass for only $540.
In August 2022, Cyble first documented Typhon’s many features. These capabilities included clipboard hijacking, screenshot taking, and data theft from cryptocurrency wallets as well as messaging apps such as FTP, VPN, browsers , and gaming.
Based on another theft malware called Prynt Stealer, Typhon is also capable of delivering the XMRig cryptocurrency miner. In November 2022, Palo Alto Networks Unit 42 discovered an updated version called Typhon Reborn.
See also: HP will fix a major flaw in LaserJet printers within 90 days
On January 31, 2023, the creator of the V2 variant advertised it on XSS — a Russian dark web forum. According to Cisco Talos, this is the latest version available.
Unlike popular malware, V2 has the functionality to avoid systems located in a number of countries in the Commonwealth of Independent States. Notably absent from the list are Ukraine and Georgia, two countries that remain dangerously vulnerable to infection.
In addition to incorporating more anti-analysis and anti-virtualization checks, Typhon Reborn V2 removes its persistence capabilities, instead opting to terminate after data is extracted.

The malware ultimately transmits the collected data in a compressed file over HTTPS using the Telegram API, highlighting the ongoing abuse of the messaging platform.
According to a recent announcement by Cyble, the cybersecurity firm has identified a new strain of Python-based malware called Creal. This crypto-stealing malware is designed to target cryptocurrencyby luring them with sophisticated phishing websites that mimic reputable crypto mining services, such as Kryptex.
See also: Alcaseca: Spain's most dangerous hacker arrested
The malware is no different from Typhon Reborn, as it is equipped to capture cookies and passwords from Chromium-based web browsers, as well as data from instant messaging, gaming, and crypto wallet.
Furthermore, the source code of the malware can be found on GitHub, which enables other cybercriminals to modify it as they wish and makes it a serious risk.
Information source: thehackernews.com
