EXECUTIVE SUMMARY:
A financially motivated threat actor operating a Malware-as-a-Service (MaaS) platform has developed two new malware families: TerraStealerV2 and TerraLogger. These tools are designed for credential theft and keylogging, respectively, and are linked to a known cybercriminal ecosystem used by high-profile threat groups. The malware exhibits signs of ongoing development, with TerraStealerV2 focusing on stealing browser data and cryptocurrency wallets, while TerraLogger captures keystrokes without exfiltrating them. Both tools lack the sophistication typically seen in mature malware from this actor, suggesting they are either in early stages or being refined for future campaigns.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A financially motivated threat actor operating a Malware-as-a-Service (MaaS) platform has developed two new malware families: TerraStealerV2 and TerraLogger. These tools are designed for credential theft and keylogging, respectively, and are linked to a known cybercriminal ecosystem used by high-profile threat groups. The malware exhibits signs of ongoing development, with TerraStealerV2 focusing on stealing browser data and cryptocurrency wallets, while TerraLogger captures keystrokes without exfiltrating them. Both tools lack the sophistication typically seen in mature malware from this actor, suggesting they are either in early stages or being refined for future campaigns.[emaillocker id="1283"]
TerraStealerV2 extracts credentials from Chrome’s "Login Data" database but fails to bypass modern encryption protections, indicating outdated or incomplete development. It exfiltrates stolen data to Telegram and a domain (wetransfersio) and is distributed via multiple file formats, including LNK and MSI files. The malware abuses legitimate Windows utilities like regsvr32exe to evade detection. In contrast, TerraLogger operates as a standalone keylogger, recording keystrokes to local files without sending data to a remote server. It uses a common keyboard-hooking technique and stores logs in plaintext, with minor updates observed in recent samples. The lack of exfiltration mechanisms suggests it may be part of a larger modular framework.
The discovery of these malware families highlights the continuous evolution of tools used by cybercriminal networks. While TerraStealerV2 and TerraLogger currently lack advanced stealth or persistence mechanisms, their development aligns with the threat actor’s history of refining malware for credential theft and surveillance. The use of multiple distribution methods and evasion techniques indicates a deliberate effort to maximize infection rates. As these tools mature, they may incorporate more sophisticated features, increasing their effectiveness in future campaigns. Organizations should remain vigilant for related activity, particularly phishing attempts delivering these payloads.
THREAT PROFILE:
| Tactics | Technique ID | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1218 | System Binary Proxy Execution |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1555 | Credentials from Password Stores |
| Discovery | T1083 | File and Directory Discovery |
| Collection | T1056 | Input Capture |
| T1113 | Screen Capture | |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]