The researchers at Bitdefender spotted a new evasive cryptocurrency stealer dubbed BHUNT which could exfiltrate wallet (Exodus, Electrum, Atomic, Jaxx, Ethereum, Bitcoin, Litecoin wallets) contents, passwords stored in the browser, and data from the clipboard.
BHUNT is a modular stealer written in .NET, its binary files are heavily encrypted with commercial packers such as Themida and VMProtect.
Researchers identified samples which are digitally signed with a digital certificate issued to a software company, but Bitdefender pointed out that the digital certificate does not match the binaries.
The samples analyzed by Bitdefender uses encrypted configuration scripts that are downloaded from public Pastebin pages. The malware spreads via cracked software installers and infected users in several countries such as Australia, Egypt, Germany, India, Indonesia, Japan, Malaysia, Norway, Singapore, South Africa, Spain, and the US.
The attack chain starts with the execution of an initial dropper, which writes to disk heavily-encrypted binaries that are then used to launch the main component of BHUNT.
The cryptocurrency stealer has a modular structure, some of the modules analyzed by the researchers are:
- blackjack – steal wallet files
- chaos-crew – establish persistence and download additional payloads
- golden7 – steal account tokens from Firefox and Chrome as well as passwords from clipboard
- Sweet_Bonanza – steal stored passwords from supported browsers (i.e. Internet Explorer, Firefox, Chrome, Opera, and Safari)
- mrpropper – delete artifacts from infected system
BHUNT stealer exfiltrates information about cryptocurrency wallets and passwords, with the aim of financial gain. Its code is straightforward and the delivery method is similar to that of existing successful malware, like Redline stealer.
The researchers recommend to keep your security solution up to date and never turn it off, especially if it blocks the installation of such software.

















Comments