HomeSecurityMars Stealer malware distributed via OpenOffice ads on Google

Mars Stealer malware distributed via OpenOffice ads on Google

Researchers have discovered that the new Mars Stealer malware is distributed through OpenOffice ads on Google.

Mars Stealer, a relatively new variant of information-stealing, is increasingly being used in attacks. Threat analysts are now identifying the first large-scale campaigns using the malware.

See also: Europol dismantles massive investment fraud operation

Mars Stealer was discovered in June 2021, as a redesigned version of the Oski malware that stopped working in 2020. The new version (Mars Stealer) includes more information-stealing capabilities that target a wide range of applications.

Mars Stealer OpenOffice

The malware began to be promoted on hacking forums at affordable prices ($140-$160). Initially, it was not that popular, but the abrupt withdrawal of Raccoon Stealer forced cybercriminals to look for alternatives.

More and more malicious users have started using Mars Stealer and researchers believe that it will be used in many hacking campaigns. Mars Stealer is distributed through social engineering techniques, malspam campaigns, software cracks and keygens.

For example, threat analysts at Morphisec report that they have identified several of these new campaigns, including one that uses a cracked version of the malware that is distributed with instructions on how to use it.

Mars Stealer: OpenOffice Campaign

According to Morphisec, a new Mars Stealer distribution campaign is using Google Ads to rank cloned OpenOffice sites high in Canadian search results.

OpenOffice was once a popular open-source office suite that is now owned by the Apache foundation and has been almost completely replaced by LibreOffice, which started as a fork in 2010.

See also: Verblecon malware: Used in cryptocurrency mining attacks

However, OpenOffice still has a respectable number of daily downloads from people looking for a free document and spreadsheet editor. It is likely that the Mars Stealer operators did not clone the more popular LibreOffice because that would have resulted in a quick removal due to numerous user reports.

According to Morphisec researchers, the OpenOffice installer on the fake OpenOffice site is, in fact, a Mars Stealer executable along with the Babadeda crypter or Autoit loader.

Mars Stealer malware distributed via OpenOffice ads on Google

Due to an error in the configuration instructions of the cracked version, the operator has exposed the victims' "logs" directory, giving full access to any visitor. A log is a zip file containing data stolen via a trojan and uploaded to the attackers' command and control servers.

In this campaign, the stolen information produced by Mars Stealer appears to contain items such as browser auto-fill data, browser extension data, credit cards, IP address, country code, and time zone.

The operators were also infected with the Mars Stealer copy during debugging, and thus their own information was exposed.

See also: SunCrypt ransomware: New version with more features

This mistake allowed researchers to attribute the attacks to a Russian-speaking user and discover the attacker's GitLab accounts, stolen credentials used to pay for Google Ads, and more.

Mars Stealer: A new threat to crypto assets?

Threat analysts believe that Mars Stealer is an emerging threat, as the malware is being promoted on more than 47 darknet sites and hacking forums, Telegram channels, and other "unofficial" distribution channels, such as cracked packs.

Morphisec says that the operators of these info-stealers are largely focused on crypto assets.

To protect yourself from such malware, make sure you open official sites and not Google Ad results.

More details about the Mars Stealer malware and its operation can be read in 3xp0rt.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS