A new malware-as-a-service, called "Eternity Project," provides hackers with a kit of useful tools that can be customized with different modules depending on the attack being carried out.
See also: Nerbian RAT: New malware distributed via COVID-19-themed emails

The malware toolkit may include an information-stealing program, a cryptominer, a clipper, a ransomware, a worm distributor, and soon, a DDoS bot, each purchased separately.
All of the above is promoted in an exclusive Telegram with over 500 members, where authors post release notes for updates, usage instructions, and discuss feature suggestions.
Those who have purchased the Eternity Project malware kit can use the Telegram Bot to automatically generate the binary, after selecting which features they want to enable and paying for them with cryptocurrency.
Starting with info-stealer, which sells for $260/year, this tool extracts passwords, credit cards, bookmarks, cookies, and autofill data stored in more than twenty web browsers.
See also: Bitter cyberespionage group targets South Asian governments with new malware
Additionally, it can steal information from cryptocurrency extensions or even wallets and also targets ten password managers, VPN, messengers, and gaming clients.

The mining unit costs $90/year and features task manager hiding, automatic restart when it stops working, and startup persistence.
Clipper sells for $110 and is a utility that monitors the clipboard for cryptocurrency wallet addresses to replace them with wallets under the operator's control.
The developer sells the Eternity Worm for $390, giving the malware the ability to spread itself via USB drives, local network shares, local files, cloud drives, Python projects (via the interpreter), Discord accounts, and Telegram accounts.
See also: FluBot malware: Distributed via SMS and targets users in Finland
Finally, the Eternity ransomware module is the most expensive at $490. It supports offline encryption using a combination of AES and RSA and targets documents, photos, and databases. The ransomware module also offers an option to set a timer that makes files completely unrecoverable when it expires. This puts additional pressure on the victim to pay the ransom.
Cyble analysts who discovered Eternity Project said that while they haven't had the chance to examine all the modules yet, they have seen samples of malware circulating and being actively used, and all user comments on Telegram indicate that this is a real threat.
