HomeSecurityChrome, Edge browsers targeted in Zaraza bot malware attacks

Chrome, Edge browsers targeted in Zaraza bot malware attacks

Researchers have discovered a new variant of the Zaraza malware that steals log-in credentials from web browsers including Google Chrome, Microsoft Edge, Opera, and Brave. The malicious actors use Telegram servers as a command-and-control platform to transfer banking links and cryptocurrencies obtained from infected computers.

Zaraza

Cybersecurity firm Uptycs recently published a report on the increasing use of Telegram to distribute and market the Zaraza malware. It is believed that those behind this campaign are linked to Russia, as “Zaraza” translates to “infection” in Russian. This further highlights how critical it is for both organizations and individuals to be vigilant against cyber threats.

The Zaraza bot actively targets nearly 40 web browsers, but Apple 's Safari and the Mozilla Foundation's Firefox are not among the targets. Unfortunately, Uptycs' examination of the issue did not include any information about the adversaries' initial steps or the techniques used to infect target computers.

“Attackers… use the stolen data for malicious purposes, including identity theft, financial fraud , and unauthorized access to personal and business accounts,” Uptycs said.

It is noteworthy that the Zaraza malware can decrypt the encryption used by targeted browsers to secure stored passwords . According to the researchers, “the web browser on the system stores credentials in two encrypted formats as a default security measure; however, the Zaraza bot is able to decrypt both of these formats.” As expected, this means that users are strongly advised to be careful when using their devices and opt for stronger security measures , if necessary.

The Zaraza bot appears to be a key player in an organized criminal scheme, with those involved able to purchase access from the primary malware provider. Additionally, threat actors are increasingly using Telegram Messenger as a C2 platform due to its ability to distribute malicious code and transfer data while avoiding detection . Uptycs has observed this trend among adversaries who consistently use Telegram for malicious activities .

Zaraza is distributed as a 64-bit binary compiled using the C# programming language and contains Russian Cyrillic characters in code . After scanning the infected device, the malware creates an “output.txt” file in a new subfolder in the Temp directory. “After successfully extracting the encrypted passwords from the browser, the attacker then saved this data to the output.txt file,” the researchers said.

Chrome, Edge browsers targeted in Zaraza bot malware attacks

In addition to the output.txt file, a screenshot of the target's computer system is saved and then uploaded to the Telegram channel.

Uptyc has provided a copy of a YARA rule for security professionals to use on any EDR/XDR vendor with YARA rule detection capabilities and manually remove malicious files. An indicator of compromise includes an MD5 file hash (41D5FDA21CF991734793DF190FF078BA).

Source of information: scmagazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS