Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
The threat actor who created the information-stealing malware called Typhon Reborn has reappeared with an upgraded version (V2) that comes with enhanced abilities to evade detection and resist investigation. The stealer steals sensitive data and exfiltrates it by using Telegram API to attackers. Typhon Reborn is also capable of delivering the XMRig cryptocurrency miner. This updated version contains improved stealth and file-grabber functions and more advanced anti-analysis mechanisms. The second version (V2) offers options for avoiding infection of CIS-based computer systems. However, Georgia and Ukraine are excluded from the list.
Typhon Reborn checks the malware configuration before running to see if anti-analysis is enabled. If it is turned on, the malware will try to run several anti-analysis tests to see if it is being run in a sandbox or an analysis environment. If it detects that it is running in sandbox or analysis environment, it will create a batch file in the temp directory. Then the batch file will be executed, terminating the malware’s execution. If all the anti-analysis checks are passed, then the Typhon Reborn V2 will start collecting and exfiltrating sensitive data. Firstly, it will create a subdirectory under Local Appdata folder with a random name. Then the malware starts producing stealer logs, which will ultimately be prepared for exfiltration in that subdirectory. The stealer will also store Wi-Fi network information. Once just about every bit of system data has been gathered and saved, the stealer starts going through applications and gathering data in accordance with the malware's setup. The stealer is currently capable of obtaining passwords, tokens, and other sensitive data. Data can be stolen from additional apps, such as different gaming clients. After the data has been fully gathered by the stealer from compromised systems, it is compressed and exfiltrated using the Telegram API over HTTPS. The archive is later deleted from the compromised machine and its execution terminates once the attacker has successfully received the data.
The updated version of Typhon Reborn is available for purchase on the dark web for lifetime, per month, and annual subscription. The creator of the malware announced Typhon Reborn V2's arrival on January 31, 2023, on the well-known Russian-language dark web forum XSS. According to samples posted to open-access repositories, Typhon Reborn has been in use since December 2022.
Threat Profile:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1497 | Virtualization/Sandbox Evasion | |
| T1564 | Hide Artifacts | |
| T1140 | Deobfuscate/Decode Files or Information | |
| Discovery | T1082 | System Information Discovery |
| Collection | T1560 | Archive Collected Data |
| T1005 | Data from Local System | |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/04/typhon-reborn-stealer-malware.html
[/emaillocker]