Witchlogger.zip
: It targets Chrome, Firefox, and Edge to extract saved passwords and session cookies.
To steal browser credentials, cookies, keystrokes, and system metadata. WitchLogger.zip
: It monitors the clipboard for copied passwords or cryptocurrency wallet addresses. : It targets Chrome, Firefox, and Edge to
Frequently distributed via phishing emails containing the .zip archive, often disguised as an invoice, shipping document, or software update. Execution Chain : It targets Chrome
: Once the user extracts the .zip and runs the executable (e.g., WitchLogger.exe ), it often performs an "anti-analysis" check to see if it is running in a virtual machine or sandbox.
: Disconnect the infected machine from the network immediately.