HomeSecurityNew Windows-based ThirdEye malware steals sensitive data

New Windows-based ThirdEye malware steals sensitive data

A previously undocumented Windows-based information stealer called ThirdEye has been discovered, with the potential to collect sensitive data from infected computers.

See also: Priorities in preparing for a ransomware attack: people, processes and technology

ThirdEye

See also: Mobile Malware and mobile phishing sites increased in 2022

Fortinet FortiGuard Labs, which made the discovery, said it found the malware in an executable file disguised as a PDF file with the Russian name “CMK Правила оформления больничных листов.pdf.exe,” which translates to “CMK Rules for issuing sick leaves.pdf.exe.”

The malware's delivery vector is currently unknown, although the nature of the lure suggests it was used in a phishing campaign. The first ThirdEye sample was uploaded to VirusTotal on April 4, 2023, with relatively fewer features.

The evolving stealer, like other malware families of its kind, is equipped to collect system metadata, including BIOS release date and vendor, total/free space on the C drive, currently running processes, registered usernames, and volume information. The collected data is then transmitted to a command and control (C2) server.

A notable feature of the malware is that it uses the string “3rd_eye” to announce its presence to the C2 server.

There is no evidence to suggest that ThirdEye has been used by the hackers. That said, given that the majority of stolen items were uploaded to VirusTotal from Russia, it is likely that the malicious activity is targeting Russian-speaking organizations.

“While this malware is not considered sophisticated, it is designed to steal various information from compromised machines that can be used as a springboard for future attacks,” Fortinet researchers said, adding that the data collected is “valuable for understanding potential targets.”

This development comes as trojanized installers for the popular Super Mario Bros video game franchise hosted on rogue torrent sites are being used to spread cryptocurrency miners and an open-source stealer written in C# called Umbral, which spreads data of interest using Discord Webhooks.

“The combination of mining and theft activities leads to financial losses, a significant reduction in the victim’s system performance, and the depletion of valuable system resources,” Cyble said.

New Windows-based ThirdEye malware steals sensitive data

Video game users have also been targeted with Python-based ransomware and a remote access trojan called SeroXen, which has been found to exploit a commercial batch file obfuscation engine known as ScrubCrypt (also referred to as BatCloak) to evade detection. Evidence suggests that individuals involved in the development of SeroXen also contributed to the creation of ScrubCrypt.

The malware, which was advertised for sale on a clearnet website registered on March 27, 2023 before its shutdown in late May, was further promoted on Discord, TikTok, Twitter , and YouTube. A cracked version of SeroXen has also been found on criminal forums.

See also: Akira ransomware: Linux version targets VMware ESXi servers

Individuals are strongly advised to adopt a cautious attitude when encountering links and software packages associated with terms such as “cheats,” “hacks,” “cracks,” and other pieces of software related to gaining a competitive advantage, Trend Micro notes in a new SeroXen analysis.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS