Emansrepo: Python Infostealer with Tailored Email Exfiltration

Amber | Attack Report
Download PDF

Emansrepo is a Python-based infostealer, first observed in November 2023, that spreads via phishing emails disguised as purchase orders and invoices. This malware primarily targets browser directories and specific file paths, collecting sensitive data from victims. The exfiltrated data is bundled into a zip file and sent directly to the attacker’s email address. The stolen information could be leveraged in future attacks, potentially leading to further exploitation or data compromise.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox