Malware

New Bandit Stealer targets web browsers and cryptocurrency wallets

0

A new stealthy information stealer malware dubbed Bandit Stealer which targets numerous web browsers and cryptocurrency wallets was discovered by researchers at Trend Micro.

The new info-stealing malware which is written in the Go language targets only Windows systems, but according to experts it has the potential to expand to other platforms as well.

The malicious code relies on the Windows command-line utility program “runas.exe” to run programs as a different user with different permissions.

By using the tool, the malware elevates the user’s privileges and executes itself with administrative access without being detected. However, Bandit Stealer fails to use the tool because they need to provide the appropriate credentials.

Bandit Stealer performs some checks to determine if it’s running in a sandbox environment or testing environment. The malware then terminates blacklisted processes associated with anti-malware solutions.

The Bandit Stealer maintains persistence by using an entry for autorun in Windows Registry.

The info-stealer collects a broad range of information and stores it in the “vicinfo” folder in <C:\Users\<Username>\AppData\Local\>.

Additionally, the malware scans for specific browser extensions associated with cryptocurrency wallets by checking the path of the browser extensions.

The malware can also collect Telegram sessions to gain unauthorized access, allowing impersonation and malicious actions such as accessing private messages and data associated with the compromised account

This malware might have been downloaded by users unknowingly while visiting malicious websites or by opening the attachment of a phishing email.

The attachment is a self-extracting archive that executes the hot.exe file to start the infection process. It also opens a harmless Word document to avoid raising suspicion.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Data stealing malware hidden in popular Android screen recorder app

Previous article

New Horabot campaign targets Gmail and Outlook accounts

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *