PPI (pay-per-install) service PrivateLoader is distributing a brand new info-stealer malware called “RisePro” that steals user information via fake crack sites.
RisePro was created to make it easier for criminals to steal crypto wallets, credit cards, and passwords from victims’ infected devices.
See also: Hacker says he’s selling data of 400 million Twitter users

This week, analysts at Flashpoint and Sekoia discovered the malware, and the two cybersecurity firms have since confirmed that RisePro is an info-stealer that had previously gone unnoticed but is now spreading via fake crack software and key generators.
Thousands of logs , or data packets stolen from infected devices, are already being sold on Russian dark web markets, according to Flashpoint.
Sekoia discovered several similarities in the code between PrivateLoader and RisePro, suggesting that the malware distribution platform is likely now spreading its own info-stealer.

RisePro features and information.
RisePro is a malware written in C++ that may have been influenced by Vidar (password stealing malware), according to Flashpoint, as it uses the same embedded DLL dependencies.
Sekoia further explains that some RisePro samples embed DLLs, while in other samples, it retrieves them via POST requests from the C2 server.
The info-stealer malware takes “fingerprints” of systems by checking registry keys and then records the stolen information in a text file, takes a screenshot and sends it back to the attacker in a .zip file.

As mentioned below, RisePro attempts to steal a variety of data from programs, browsers, crypro wallets and browser extensions as mentioned below:
Browsers: Google Chrome, Firefox, Maxthon3, K-Melon, Sputnik, Nichrome, Uran, Chromodo, Netbox, Comodo, Torch, Orbitum, QIP Surf, Coowon, CatalinaGroup Citrio, Chromium, Elements, Vivaldi, Chedot, CentBrowser, 7start, ChomePlus, Iridium, Amigo, Opera, Brave, CryptoTab, Yandex, IceDragon, BlackHaw, Pale Moon, Atom.
Extensions: Wombat, CloverWallet, NeoLine, RoninWallet, LiqualityWallet, EQUALWallet, Guarda, Coinbase, MathWallet, NiftyWallet, Yoroi, BinanceChainWallet, TronLink, Phantom, Oxygen, PaliWallet, PaliWallet, PaliWallet, Bolt X, ForboleX, XDEFI Wallet, Maiar DeFi Wallet.
Software: Discord, battle.net, Authy Desktop.
Cryptocurrency assets: Bitcoin, Dogecoin, Anoncoin, BBQCoin, BBQCoin, DashCore, Florincoin, Franko, Freicoin, GoldCoin (GLD), IOCoin, Infinitecoin, Ixcoin, Megacoin, Mincoin, Namecoin, Primecoin, Terracoin, YACoin, Zcash, devcoin, digitalcoin, Litecoin, Reddcoin.
In addition to the above, RisePro can scan the filesystem for valuable data, such as receipts containing credit card information.
See also: eBay: Biometric devices contained US military data
The Appearance of PrivateLoader and How It Relates to RisePro
PrivateLoader, a malware PPI service, disguises itself as software cracks, key generators , and game modifications (mods). PrivateLoader uses its own network of fake and compromised sites to distribute the malware, with the first report being made in February 2022. Intel471 was the first to spot it, and in May 2022 Trend Micro noticed that PrivateLoader was promoting a new remote access trojan (RAT) called “NetDooka”. Until recently, PrivateLoader almost exclusively distributed either RedLine or Raccoon, two popular info-stealers. Now that RisePro has been added, Sekoia says it has discovered many similarities in the code of the new malware and PrivateLoader. The similarities include obfuscation techniques, obfuscation of HTTP messages, and obfuscation of HTTP ports.

It is possible that RisePro was created by the same people who created PrivateLoader.
Another possibility is that the RisePro malware is an evolution of PrivateLoader or that it was created by a former developer who is now promoting a similar PPI service.
Based on all the evidence gathered so far, Sekoia has not been able to determine the exact connection between the two.
Information source: bleepingcomputer.com
