# Hackers Adding More Capabilities to Open Source Malware

**<mark>微信 smartcat9999</mark>**

---

**<mark>September 3, 2023</mark>**

Researchers said that they observed an increase in the emergence of **<mark>new stealers being offered for sale or rent on various underground forums and marketplaces</mark>**.

Edmund Brumaghin, threat researcher at Cisco Talos said they assess with moderate confidence that **<mark>multiple entities are modifying the code base of SapphireStealer to support additional data exfiltration mechanisms </mark>** leading to the creation of several variants.

The newly compiled versions of the malware began "**<mark>being uploaded to public malware repositories</mark>** beginning in mid-January 2023, **<mark>with consistent upload activity</mark>** being observed through the first half of 2023."

Researchers observed that the malware samples are currently **<mark>being used by multiple threat actors and various variants</mark>** of this threat are already in the wild with threat actors improving its efficiency and effectiveness over time.

The malware is **<mark>capable of stealing sensitive information</mark>** from infected systems including host information, screenshots, cached browser credentials and files stored on the system that match a predefined list of file extensions. It also attempts **<mark>to determine the presence of credential databases for browser applications including Chrome, Yandex, Edge and Opera</mark>**.

Once executed, the malware creates a working directory, and a **<mark>file grabber executes and attempts to locate any files stored within the victim's Desktop folder</mark>** that match a list of file extensions including .txt, .pdf, .doc, .docx, .xml, .img, .jpg and .png.

The malware then **<mark>creates a compressed archive called </mark>** [**<mark>log.zip</mark>**](http://log.zip) containing all of the logs and the data is **<mark>transmitted to the attacke</mark>**r via Simple Mail Transfer Protocol "using credentials defined in the portion of code responsible for crafting and sending the message."

When the logs are successfully exfiltrated, the **<mark>malware deletes the working directory created earlier and terminates execution</mark>**.

"One of the byproducts of readily available and open source malware codebases is that **<mark> the barrier to entry into financially motivated cybercrime has continued to decrease over time</mark>**"

Stealers enables attackers **<mark>with less operational expertise to conduct an attack</mark>**, but it can be extremely damaging to corporate environments as the data stolen is often leveraged for additional attacks later.
