Possible FakeWallet Wallet Exfiltration via Structured POST Parameters (via proxy)

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects POST requests carrying the FakeWallet specific parameters ciyu, ciyuType and wallet used to transmit stolen cryptocurrency wallet material to the operator. This parameter layout is unique to the FakeWallet iOS stealer campaign. Detecting the structured parameters surfaces exfiltration even when the destination domain changes.

Related detections9 linkedT1041 — drag to rearrange
Malicious FakeWallet Crypto Stealer C2 via Rsakey Endpoints (via proxy)
Possible Malicious MCP Server Credential Exfiltration via DevTools-Assistant Agent (via proxy)
Suspicious curl POST Exfiltration of Archive from tmp Staging Folder via process_creation
Malicious Phishing Data Exfiltration to SheetBest API by GitBait Campaign (via proxy)
Malicious PowerShell Base64 Exfiltration to save.php via EKZ Stealer
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Suspicious Exfiltration of Environment File via wget POST
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Possible FakeWallet Wallet Exfiltration via Structured POST Parameters (via proxy)
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.