Product
medium
threat
Detection of Unauthorized WinSCP Credential Access
1 rule 1 TTP 2 IOCsThis analytic detects unauthorized access to the WinSCP security configuration folder, which stores sensitive SSH and FTP credentials, by processes other than WinSCP, leveraging Windows Security Event 4663 to identify abnormal read or access attempts often indicative of credential-stealing malware like Phantom Stealer.
WinSCP
Phantom Stealer
credential-theft
infostealer
windows
1r
1t
2i
high
advisory
WinSCP Credential Access by Information Stealers
1 rule 1 TTPInformation-stealing malware such as Phantom Stealer targets WinSCP's security configuration folder to harvest sensitive SSH and FTP credentials, leading to unauthorized access to remote systems and potential lateral movement.
WinSCP
credential-theft
infostealer
windows
data-exfiltration
1r
1t