
Security researchers from Morphisec have discovered a malware campaign that uses a relatively new trojan and targets businesses and higher education institutions. Its purpose is to steal usernames, passwords and other personal information. It also has the ability to create a permanent backdoor on compromised systems. The trojan is called Jupyter and was discovered on the network of a higher education institution in the US. Researchers believe that the malware has been in use since at least May.
The attack primarily targets data from Chromium, Firefox, and Chrome browsers, but also creates a backdoor on compromised systems, allowing attackers to execute PowerShell scripts and commands, as well as download and execute other malware.
The Jupyter installer is disguised as a zip file , and often uses Microsoft Word icons or has a specific file name that creates the feeling that it needs to be opened urgently (important document).
If the installer is executed, it will install legitimate tools in an attempt to hide the real purpose of the installation/download. It then runs malicious programs in temporary folders in the background.

Once fully installed on the victim, the Jupyter trojan steals information including usernames, passwords, browsing history, and cookies and sends it to a command and control server, apparently controlled by the criminals. According to researchers, the creator of the Jupyter trojan is constantly changing the code to collect more information, while also trying to make it harder to detect.
At this time, it is unclear what the criminals behind the Jupyter trojan are trying to do. Most likely, they are using it to steal information and gain further access to corporate and educational networks. In addition, they could steal highly sensitive and important data to sell to other criminals (giving them access to the victims' networks).
Morphisec researchers believe that the Jupyter trojan originated in Russia. Analysis showed that the malware was connected to command and control servers located in Russia. Further analysis showed connections to a Russian hacking forum.
Many of the command servers are currently down, but the control panel is still active. This means that malware campaigns using Jupyter are likely still ongoing.
Source: ZDNet
