The Computer Emergency Response Team (CERT-UA) of Ukraine is warning about phishing emails distributing the Jester Stealer malware and trying to trick users into opening malicious attachments, warning them of impending chemical attacks.
As the war between Russia and Ukraine continues, many fear that things could get worse.
See also: Microsoft: Patches for Azure flaw that allows RCE attacks

Ukrainians live in fear, and cybercriminals are exploiting it. They send phishing emails warning of chemical attacksto attract victims' attention and increase the chances of them opening malicious attachments that lead to infection of systems with the Jester Stealer malware.
The phishing email stated (translated text):
"Today, information was received that chemical weapons will be used at 01.00 at night, the authorities are trying to hide it so that the population does not panic. Urgently inform yourself about the places where chemical weapons will be used and the special shelters where we will be safe.".
Please help us disseminate the information attached to the document as widely as possible.
We must save as many lives as possible!".
See also: A ransomware attack and the COVID-19 pandemic shut down Lincoln College
At the end of the phishing email warning about chemical attacks, there are attached XLS documents with malicious macros . If the recipient opens the file and enables the macros, an EXE payload will be downloaded from a remote source and then executed on the computer .

According to CERT-UA, the executable files are downloaded from compromised websites and not directly from infrastructure controlled by the attackers.
According to experts, the payload running on the victim's system is the Jester Stealer malware, which steals information and has been quite popular recently thanks to its extensive capabilities.
Jester Stealer can steal data stored in browsers, such as account passwords, email client messages, chat conversations, and cryptocurrency wallet data. The stolen data is then uploaded to a remote server and collected by the attackers. Cybercriminals can sell this data to other malicious users or use it for other attacks.
See also: DCRat: This cheap malware is surprisingly effective
According to CERT-UA, the operators of the Jester Stealer malware have made it difficult to analyze the malware in virtual machines.
However, there seems to be no persistence mechanism. So if the program is closed and deleted, it will not start again.
At present, Ukraine has not linked the phishing emails to any specific group.
Source: www.bleepingcomputer.com

