
Recently, a new threat has been discovered, the TroyStealer info stealer, first reported by Abuse.ch and targeting Portuguese users.
New malware appears every day , so all users must be on guard and keep their systems secure.
TroyStealer info stealer is a Trojan designed to steal information from a system. The malware collects information, such as usernames and passwords stored in web browsers. It then sends it to another system via email. It also acts as a keylogger, which means it monitors the victim's keystrokes. These keystrokes can reveal other sensitive information.
The email that victims receive reports problems with their bank account.
In detail, the malware checks if it is running inside a VM and stops execution. If not, TroyStealer continues to run and a new process is created using injection technique. After that, the collection process data.
During the execution of TroyStealer, the following steps take place:
- Collection of victim data (credentials from browser and email)
- HKEY_CURRENT_USER\Software\Paltalk passwords collection
- Deleting specific browser files
- Get details of security products installed on the device
- Download the operating system version
- Keylogging
- Sending stolen information to the attacker via email
The malware verifies that there is a valid Internet, via a speed test site. If there is, it establishes SMTP communication with the validated email server and sends the victim's credentials via email.

Malware can cause great damage to a business or even infect a large number of users. What can we do to protect ourselves, to some extent, from malicious software?
- Regular updating of systems
- Good control of the emails we receive
- Beware of emails related to banking transactions, invoices, COVID-19, anything that seems strange
- Logging out of accounts and the internetat the end of the day
- Access only safe and trusted sites
- Using an antivirus program
- Backup
