HomeSecurityMrAnon Stealer: Malware that pretends to be a booking service

MrAnon Stealer: Malware that pretends to be a booking service

A phishing campaign is being observed sending a malicious information-stealing software called MrAnon Stealer to unsuspecting victims by posing as a hotel room booking service via seemingly innocent PDFs.

MrAnon Stealer

See more: Telekopye: Telegram bot that carries out large-scale phishing scams

“This malware is a Python-based information-stealing system that is compressed with cx-Freeze to avoid detection,” said Cara Lin, a researcher at Fortinet FortiGuard Labs. MrAnon Stealer steals victims’ credentials, as well as information about the system, browser sessions, and other information. There is evidence to suggest that Germany is the primary target of an attack from November 2023.

Posing as a company that offers hotel room booking services, the spam email contains a PDF file that – after urging the recipient to download an updated version of Adobe Flash – upon opening, infects the system. This process leads to the execution of .NET executables and PowerShell scripts to implement a destructive Python script . This script is capable of collecting data from multiple applications and exploiting it on a public file sharing website and the threat actor’s Telegram channel. It can also extract information from instant messaging applications, VPN clients , and files that match a wanted list of extensions.

MrAnon Stealer is available from its creators at a price of $500 per month (or $750 for two months), accompanied by an encryptor ($250 per month) and a stealthy loader ($250 per month).

“The campaign initially spread in July and August with Cstealer, but shifted to distributing MrAnon Stealer in October and November,” Lin said. “This pattern suggests a strategic approach that involves the continued use of phishing emails to spread Python -based theft platforms.”

Read more: Insomniac Games: Hit by Rhysida ransomware attack

MrAnon Stealer

The revelation is coming as China-linked Mustang Panda appears to be involved in a phishing campaign targeting the Taiwanese government and diplomats. The purpose of the attack is to deploy SmugX, a new variant of the PlugX backdoor previously uncovered by Check Point in July 2023.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS