The source code of an info-stealer malware based on the Rusthas been circulating on hacking forums since July 3, with security analysts already reporting that the malware is being actively used in attacks.

Its creator claims that the malware was developed in just six hours and is quite effective at avoiding detection, with VirusTotal showing a detection rate of around 22%.
As the info-stealer malware actors threat to target multiple operating systems. However, in its current form, the new info-stealer only targets Windows.
See also: T-Mobile: Agrees to pay $350 million to customers for last year's data breach
Malware capabilities
Analysts at cybersecurity firm Cyble, who examined the new info-stealer and named it “Luca Stealer,” report that the malware has the usual capabilities of this type of malware. Specifically, when executed, the malware attempts to steal data from thirty Chromium-based browsers. The data it steals includes stored credit cards, login credentials, and cookies.
Additionally, the malware targets a range of “cold” cryptocurrency and “hot” wallet browser addons, Steam accounts, Discord tokens, Ubisoft Play, chat apps, gaming apps , and more.
Where Luca Stealer stands out from other info-stealers is its focus on password manager browser addons, aiming to steal locally stored data from 17 such applications.
According to the researchers, this info-stealer also takes screenshots and saves them as .png files, while also performing a “whoami” to create a system profile and send the details to its operators.
See also: SonicWall warns of critical SQL injection flaw
However, it is worth noting that Luca Stealer lacks another feature that is common in other info-stealers. It does not have a clipper, which is used to modify the contents of the clipboard for the purpose of hacking cryptocurrency transactions.

The removal of the stolen data is done via Discord webhooks or Telegram bots, depending on whether the extracted file is over 50 MB or not. The malware will use a Discord webhook to send the data back to the attackers, for larger files.
The stolen data is placed inside a ZIP file accompanied by a summary of the contents, so that the operator can assess the extent of the theft at a glance.
Luca Stealer: New big threat?
Cyble reports that it has seen at least 25 cases of Luca Stealer being used. This means that some cybercriminals have leveraged the source code of the info-stealer malware that is offered for free on hacking forums. However, we cannot know whether this new malware will see mass deployment.
See also: Entrust hacked by ransomware gang
However, the fact that it is offered for free with source code could tempt criminals, given that most info-stealers are sold on a monthly subscription. Also, let's not forget that Luca is written in Rust, which means that porting it to Linux or macOS is not complicated.

For your protection, Cyble researchers recommend:
- Avoid downloading files from untrusted sources.
- Clear browsing history and reset passwords at regular intervals.
- Enable automatic software updates on your computer, mobile phone, and other connected devices.
- Using a reliable antivirus program for all your devices.
- Avoid opening untrusted links and email attachments without first verifying their authenticity.
- Employee training on various cyber threats
- Block URLs that could be used to spread malware, e.g. Torrent/Warez.
- Network-level beacon monitoring to block data by malware.
- Enable Data Loss Prevention (DLP) solution on employee systems.
Source: www.bleepingcomputer.com
