New BunnyLoader malware helps to steal credentials, crypto coins

New BunnyLoader malware helps to steal credentials, crypto coins

A new malware-as-a-service (MaaS) threat known as “BunnyLoader” is being advertised for sale on various underground forums, according to a new report from cloud security firm Zscaler ThreatLabz.

Written in C/C++, BunnyLoader is filless, operating mostly in memory. The malware, which is under active development, comes with a slew of functionalities, such as the ability to download and execute a second-stage payload, steal browser credentials and system information, log keystrokes, and thwart analysis attempts. It can also monitor the victim’s clipboard and replace cryptocurrency wallet addresses with actor-controlled crypto wallets, and supports remote command execution.

The BunnyLoader command-and-control panel showcases a list of various tasks, including downloading and executing additional malware, keylogging, stealing credentials, manipulating a victim’s clipboard to steal cryptocurrency, and running remote commands on the infected machine.

Since its initial release on September 4, 2023, BunnyLoader went through several feature updates, introducing new functionalities. Currently, the tool is being sold for $250, while the ‘private stub’ version, which implements more advanced features is being offered for $350.

Back to the list

Latest Posts

Cyber Security Week in Review: July 4, 2025

Cyber Security Week in Review: July 4, 2025

In brief: Google patches Chrome 0Day, the US is on the hunt for North Korean IT workers, and more.
4 July 2025
AI chatbots fall for phishing scams

AI chatbots fall for phishing scams

The models provided the correct URL only 66% of the time; nearly 30% of responses pointed users to dead or suspended domains.
3 July 2025
Chinese hackers exploited Ivanti flaws in attacks against French government

Chinese hackers exploited Ivanti flaws in attacks against French government

ANSSI believes that the Houken campaign is operated by ‘UNC5174’, an entity believed to act as an initial access broker for China’s Ministry of State Security.
2 July 2025