Skip to main content

Command Palette

Search for a command to run...

Hackers Adding More Capabilities to Open Source Malware

Published
2 min readView as Markdown
Hackers Adding More Capabilities to Open Source Malware
C
酷愛計算機技術Ardently Love Computer Technology 長期關註反洗錢反欺詐Long-term Focus on Anti-Money Laundering and Anti-Fraud 精通支付結算的技術、系統、流程和製度Proficient in the Technology, System, Process and Institution of Payment and Settlement

微信 smartcat9999


September 3, 2023

Researchers said that they observed an increase in the emergence of new stealers being offered for sale or rent on various underground forums and marketplaces.

Edmund Brumaghin, threat researcher at Cisco Talos said they assess with moderate confidence that multiple entities are modifying the code base of SapphireStealer to support additional data exfiltration mechanisms leading to the creation of several variants.

The newly compiled versions of the malware began "being uploaded to public malware repositories beginning in mid-January 2023, with consistent upload activity being observed through the first half of 2023."

Researchers observed that the malware samples are currently being used by multiple threat actors and various variants of this threat are already in the wild with threat actors improving its efficiency and effectiveness over time.

The malware is capable of stealing sensitive information from infected systems including host information, screenshots, cached browser credentials and files stored on the system that match a predefined list of file extensions. It also attempts to determine the presence of credential databases for browser applications including Chrome, Yandex, Edge and Opera.

Once executed, the malware creates a working directory, and a file grabber executes and attempts to locate any files stored within the victim's Desktop folder that match a list of file extensions including .txt, .pdf, .doc, .docx, .xml, .img, .jpg and .png.

The malware then creates a compressed archive called log.zip containing all of the logs and the data is transmitted to the attacker via Simple Mail Transfer Protocol "using credentials defined in the portion of code responsible for crafting and sending the message."

When the logs are successfully exfiltrated, the malware deletes the working directory created earlier and terminates execution.

"One of the byproducts of readily available and open source malware codebases is that the barrier to entry into financially motivated cybercrime has continued to decrease over time"

Stealers enables attackers with less operational expertise to conduct an attack, but it can be extremely damaging to corporate environments as the data stolen is often leveraged for additional attacks later.

More from this blog

Penetration Test、Python、Weaponization

721 posts

微信 smartcat9999 反欺詐Anti-Fraud 反洗錢Anti-Money Laundering 反逃稅Anti-Tax Evasion 滲透測試Penetration Test 武器化Weaponization