Researchers discovered a new Windows-based information stealer called Meduza Stealer which is actively developed by its authors to evade detection by software solutions.
The Meduza Stealer can steal browsing activities and extract a wide array of browser-related data, including login credentials, browsing history and bookmarks. The malware also targets crypto wallet extensions, password managers, and 2FA extensions.
However, no specific attacks have been attributed to the Meduza Stealer to date. The malware admin declared that their operations do not involve any ransom activities.
The malware which was discovered by researchers at Uptycs, prevents execution if the C2 server is unreachable. The binary does not employ obfuscation techniques, but the malicious code has a low detection rate.
It’s also designed to abort if a victim’s location is in the stealer’s predefined list of excluded countries, which consists of the Commonwealth of Independent States (CIS) and Turkmenistan.
Meduza Stealer, besides gathering data from 19 password manager apps, 76 crypto wallets, 95 web browsers, Discord, Steam, and system metadata, harvests miner-related Windows Registry entries as well as a list of installed games, indicating a broader financial motive.
It is currently being offered for sale on underground forums such as XSS and Exploit.in and a dedicated Telegram channel as a recurring subscription that costs $199 per month, $399 for three months, or $1,199 for a lifetime license.
The information stolen by the malware is made available through a user-friendly web panel. The subscribers can download or delete the stolen data directly from the web page, granting them an unprecedented level of control over their information.
Image Credits : Twitter

















Comments