Summary:
A new malware called Bandit Stealer is becoming popular among hackers due to its ability to steal information from web browsers and cryptocurrency wallets undetected. Although it currently targets Windows systems, it has the potential to spread to other platforms since it was developed using the versatile Go programming language. The malware community is actively promoting and raising awareness about Bandit Stealer, increasing its threat level.[/subscribe_to_unlock_form]
Summary:
A new malware called Bandit Stealer is becoming popular among hackers due to its ability to steal information from web browsers and cryptocurrency wallets undetected. Although it currently targets Windows systems, it has the potential to spread to other platforms since it was developed using the versatile Go programming language. The malware community is actively promoting and raising awareness about Bandit Stealer, increasing its threat level.[emaillocker id="1283"]
It attempts to utilize the Windows utility program runas.exe to elevate its privileges and evade security measures. However, Microsoft has implemented security restrictions and access controls to prevent unauthorized use of runas.exe, making it difficult for the malware to execute malicious activities as an administrator. The malware requires appropriate credentials to successfully run with elevated privileges, which limits its effectiveness in exploiting this particular Windows feature. The malware checks for sandbox environments and alters its behavior accordingly to avoid detection. It downloads a blacklist containing various identifiers used to detect sandbox or testing environments from a Pastebin link. The malware compares network addresses, hardware IDs, and hostnames with the entries in the blacklist to identify potential sandbox environments. It terminates blacklisted processes associated with malware analysis tools using Linux-specific commands, indicating that it may be adapted from a Linux-based version. However, some of its features, such as accessing Linux-specific files and using Linux commands, are not compatible with Windows, suggesting that the malware is still in development or being adapted for Windows systems.
It establishes persistence on an infected system by creating a registry entry for autorun, ensuring that it runs every time the system starts up. The stolen information is stored in the user's local AppData directory. The malware targets Telegram sessions to gain unauthorized access and carry out malicious actions. It also searches for sensitive information in browsers, including login data, cookies, web history, and credit card details. Bandit Stealer scans for specific browser extensions related to cryptocurrency wallets and attempts to terminate processes accessing a Zip file, possibly to extract and send it to the server or Telegram.
Bandit Stealer, despite being developed for Windows systems, includes Linux commands in its binary. This suggests potential cross-platform development in the future. The malware shares similarities with other information stealers based on the use of blacklisted items like IPs and MAC addresses. The blacklist used by Bandit Stealer appears to be publicly accessible, making attribution challenging. Currently, no active threat groups associated with the malware have been identified, and its operation is still in its early stages. Additionally, the presence of the decoy application Heartsender may be linked to cracked versions available on other websites, serving as a cautionary indicator for companies and security teams to verify the legitimacy of applications before installation.
Threat Profile:
References:
The following reports contain further technical details:
[/emaillocker]