Bandit Stealer is a new info-stealer malware that targets multiple browsers and crypto wallets . Researchers at Trend Micro discovered the new malware, which is written in the Go language.

For now, the malware only targets Windows systems, but experts stressed that it could spread to other platforms.
Info-stealer attempts to exploit runas.exe, a command-line utility program in Windows operating systems (OS), which allows users to execute specific programs or commands with credentials or permissions other than those of the current user account. This elevates the user's privileges and the malware runs with administrator access, allowing the user of the utility to perform malicious activities without being detected or blocked by security.
See also: CISA: Warns federal agencies about recent Barracuda zero-day bug
However, Trend Micro states that Bandit Stealer fails to use the tool because it must provide the proper credentials.
It is worth noting that the Bandit Stealer malware performs some checks to determine whether it is running in a sandbox or testing environment.
The malware then terminates processes related to anti-malware solutions.
The Bandit Stealer malware creates and maintains persistence . Once persistence is established, the Bandit Stealer collects the stolen victim information and stores it in the “vicinfo” folder in
“In addition, the malware scans for specific browser extensions associated with cryptocurrency wallets by checking the path of the browser extensions,” the report published by Trend Micro states.
According to researchers, Bandit Stealer can also harvest Telegram sessions to gain unauthorized access, allowing for impersonation and malicious actions such as accessing private messages and data associated with the compromised account.
See also: Zyxel firewalls affected by two security flaws
How does infection occur?
Users may get info-stealer when visiting malicious websites or by opening a malicious attachment in a phishing email. The attachment is a self-extracting archive that executes the hot.exe file to start the infection process. It also opens a harmless Word document so that the user does not know that there is anything suspicious.
“While Bandit Stealer was specifically developed to operate on Windows systems, we have observed the presence of Linux commands,” concludes the report published by Trend Micro. “It is possible that these commands could be used in future attacks on multiple platforms.”

According to the researchers, developers continuously update the capabilities of the malware.
“As of this writing, we have not identified any active threat groups associated with this malware, due to its recent emergence and limited data on its operation. We have not observed any clues as to what the group may have done with the stolen information, as the malware is still in its early stages. However, an attacker could potentially exploit it for purposes such as identity theft, financial gain, data breaches, credential stuffing attacks, and account theft.“.
See also: New Russia-linked CosmicEnergy malware targets industrial systems
More details can be found in the Trend Micro report
Info-stealer malware is a serious cyber threat that affects millions of people around the world. Hackers use this malware to steal sensitive information. To protect yourself from this threat, follow these steps:
- Keep your antivirus up to date
- Avoid clicking on suspicious links
- Use strong passwords and two-factor authentication.
Cybersecurity is an ongoing process and you must continue updating your security measures and training on the latest threats to stay safe online.
Source: securityaffairs.com
