Malware targets browser variants, crypto wallets and password managers

[ad_1]

Image: Sashkin/Adone Stock

According to a report by cybersecurity firm Uptycs, new malware dubbed Meduza Stealer can steal information from a large number of browsers, password managers, and cryptocurrency wallets. The malware was developed to target Windows operating systems.

Uptycs research indicates that “no specific attacks have been attributed to date”, likely because Meduza Stealer is new malware. It is strongly suspected that Meduza Stealer is spread via the usual methods used by information thieves, such as compromised websites spreading malware and phishing emails.

Find out what happens when Medusa Stealer is launched, how the malware is promoted to cybercriminals, and tips to protect your business from this cybersecurity threat.

Jump to:

What happens when Meduza Stealer is launched?

Once Meduza Stealer is launched, the malware starts checking its geolocation using the Windows GetUserGeoID function. This feature searches for a country value based on system settings and not real geolocation information. The malware stops working if the result shows any of these 10 countries: Russia, Kazakhstan, Belarus, Georgia, Turkmenistan, Uzbekistan, Armenia, Kyrgyzstan, Moldova, and Tajikistan.

The next step for the malware is to check if it can reach the attacker’s server before it starts collecting basic information about the infected system, such as computer name, CPU/GPU details /RAM/Hardware, precise details of OS version, time zone. and current time, username, public IP address, execution path and screen resolution. Meduza Stealer also takes a screenshot. Then the malware is ready for its theft operations (Figure A).

Figure A

Meduza Stealer workflow. Image: UptycsMeduza Stealer’s massive flight capabilities

Meduza Stealer searches for data in the User Data folder; it looks for browser-related information such as browser history, cookies, identifiers, and web data. A list of 97 browser variants is embedded in the malware, showing a huge effort not to miss any data from browsers (Figure B). Chrome, Firefox, and Microsoft Edge are just three of the browsers on the list.

Figure B

List of browsers embedded in Meduza Stealer malicious code. Image: Uptycs Password Managers

Nineteen password managers are targeted by Meduza Stealer based on their extension ID (Figure C). LastPass, 1Password, and Authy are just three of the password managers listed.

Figure C

Password managers targeted by Meduza Stealer. Image: Uptycs

The malware specifically targets extensions associated with two-factor authentication and password managers with the aim of extracting data; these extensions have important information and may contain vulnerabilities. By accessing 2FA codes or exploiting weaknesses in password manager extensions, the attacker might be able to evade security protocols and gain unauthorized access to user accounts.

Cryptocurrency Wallets Must-Read Security Blanket

There are 76 cryptocurrency wallets currently targeted by Meduza Stealer.

According to Uptycs Threat Research, “The malware attempts to extract cryptocurrency wallet extensions from web browsers via software plug-ins or add-ons that allow users to easily manage their cryptocurrency assets directly in web browsers such as Chrome or Firefox.These extensions provide functionality for tasks such as monitoring account balances, carrying out details of cryptocurrency transactions.

The malware obtains configuration and associated data from different Windows registry keys:

HKCU\SOFTWARE\Etherdyne\Etherwall\geth HKCU\SOFTWARE\monero-project\monero-core HKCU\SOFTWARE\DogecoinCore\DogecoinCore-Qt HKCU\SOFTWARE\BitcoinCore\BitcoinCore-Qt HKCU\SOFTWARE\LitecoinCore\LitecoinCore-Qt HKCU\SOFTWARE \DashCore\DashCore-Qt More Targeted Applications

The Telegram Desktop app is scanned by the malware, which looks for entries in the Windows registry specific to that app.

The malware also searches for Steam game system application data that might be stored in the Windows Registry. If Steam is installed on the computer, the data that can be extracted from it includes login data, session information, user-specific settings, and other configuration data.

Discord is another application targeted by the malware, which accesses the Discord folder and collects information such as configuration and user-specific data.

How Meduza Stealer is Promoted to Cyber ​​Criminals

According to Uptycs researchers, the Meduza Stealer admin used “sophisticated marketing strategies” to promote the malware on several marketplaces and cybercriminal forums.

For starters, the actor is quick to provide screenshots of a large chunk of antivirus software detection results, showing that only one out of 26 antivirus solutions (ESET) detects it, either statically. or dynamic.

To attract more customers, access to stolen data is offered through a web panel (Figure D). Different subscription options are presented to the potential customer: one month for 199 USD, three months for 399 USD or a lifetime plan.

Figure D

Meduza Stealer web panel; sensitive data has been deleted. Image: Uptycs

Once the user subscribes, the person has full access to the Meduza Stealer web panel, which provides information such as IP addresses, computer names, country name, number of passwords stored, wallets and cookies on infected computers. Then the subscriber can download or delete the stolen data directly from the web panel. This unprecedented feature is very useful because deleting the data ensures that no other subscriber can use this information because it is immediately deleted.

How to stay safe from this cybersecurity threat

It is strongly advised to have all operating systems and software up-to-date and patched to avoid being compromised by a common vulnerability. Browsers, in particular, must be up to date; also, run as few plugins as possible to reduce the attack surface.

It is also advisable to deploy multi-factor authentication wherever possible so that an attacker cannot access corporate resources, even if they have valid credentials.

Security solutions should be deployed on endpoints and servers, with monitoring capabilities to detect threats. It is also advisable to run YARA detection rules on corporate endpoints, such as the one provided by Uptycs to detect the Meduza Stealer.

Disclosure: I work for Trend Micro, but the opinions expressed in this article are my own.

Sources

1/ https://Google.com/

2/ https://www.techrepublic.com/article/meduza-stealer-targets-browser-variants-crypto-wallets-password-managers/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts