HomeSecurityBlackGuard info-stealing malware: What we know about the new threat

BlackGuard info-stealing malware: What we know about the new threat

BlackGuard , a new info-stealing malware (used to steal data and passwords), could be a major new threat, as it seems to have already gained the attention of cybercriminals. The malware is being sold on many dark web marketplaces and forums for $700 . However, interested criminals can pay a $200 monthly subscription fee if they don't want to buy the malware forever.

See also: Zero-day in Java Spring allows remote code execution

The BlackGuard malware can steal important information from various applications, place it in a ZIP file, and send it to the malware-as-a-service (MaaS) company's C2.

Cybercriminals who have purchased a subscription can then access BlackGuard's web panel to retrieve the stolen data logs.

BlackGuard info-stealing malware

The info-stealing malware was detected and analyzed by Zscaler.

According to Bleeping Computer, the BlackGuard malware first appeared on Russian-speaking forums in January 2022 and was initially released on a small scale for testing purposes.

BlackGuard malware: Features

As we mentioned above, info-stealing malware can steal data from a wide range of applications. It can steal all types of information related to Crypto wallets, VPNs, Messengers, FTP credentials, saved browser credentials , and more. However, it seems to focus mainly on cryptocurrency assets.

Below you can see in more detail what data BlackGuard steals and from which categories of programs:

Web browsers: Info-stealing malware steals passwords, cookies, autofill, and history from Chrome, Firefox, Opera, Vivaldi, Comodo, Edge, MapleStudio, Iridium, 7Star, CentBrowser, Chedot, Kometa, Elements Browser, Epic Privacy Browser, uCozMedia, Coowon, liebao, QIP Surf, Orbitum, Amigo, Torch, 360 Browser, Maxthon3, K-Melon, Sputnik, Nichrome, CocCoc, Uran, Chromodo, BraveSoftware.

Email: Outlook

Messengers: Telegram, Discord, Signal, Pidgin, Tox, Element

Wallet browser extensions: Binance, coin98, Metamask, Phantom, Mobox, XinPay, Starcoin, Math10, BitApp, Guildwallet, iconx, Crocobit, Sollet, Slope Wallet, Swash, Finnie, KEPLR, OXYGEN, Nifty, Liquality, Rabet wallet, Auvitas wallet, Math wallet, Yoroi wallet, MTV wallet, Ronin wallet, ZilPay wallet, Exodus, Jaxx, Terra Station.

Cryptocurrency wallets: BitcoinCore, Ethereum, Monero, Exodus, AtomicWallet, DashCore, Electrum, LitecoinCore, Jaxx, Zcash, Solar, Zap, AtomicDEX, Wassabi, Binance, Frame, TokenPocket.

Others: NordVPN, OpenVPN, ProtonVpn, Steam, Totalcommander, WinSCP, Filezilla.

BlackGuard info-stealing malware: What we know about the new threat

The information collected by the info-stealing BlackGuard malware is bundled into a ZIP file and sent to the C2 server via POST request.

See also: Apple and Meta shared data with hackers pretending to be researchers

Malware has capabilities to avoid detection

Malware operators are still improving these capabilities, but BlackGuard already has some elements that make it difficult for security researchers to detect.

First, it is packed with crypter and all its strings are base64 obfuscated. This means that many antivirus tools that rely on static detection will fail to detect it.

Also, according to the researchers, the malware detects AVs that may be running on the system and tries to influence their processes and terminate their operation.

The malware also checks the victim's IP address and if it is running on a system in Russia or any other CIS country, it does not continue the infection. This could be an indication of the origin of the BlackGuard malware.

See also: Hackers steal cryptos from other hackers by promoting fake malware

A few words about info-stealing malware

Info -stealing malware steals personal and other data that can be used for further malicious activities or to generate revenue by selling it to other criminals. This category includes threats such as keyloggers, screen scrapers, spyware, adware, backdoors, and bots.

This category of malware is on the rise, with Redline, MarsStealer, Vidar Stealer, and AZORult dominating. However, it is believed that BlackGuard malware could also become very popular.

To protect yourself from information-stealing malware, avoid visiting strange sites and downloading files from untrusted sources. Finally, use two-factor authentication, protect accounts with strong passwords, and keep all your systems up to date.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS