Researchers have discovered a new variant of BunnyLoader, a stealer and malware loader, that allows the theft of information, credentials , and cryptocurrencies, while also being able to install further malware on its victims.

The new version, called BunnyLoader 3.0, was announced by its developer, Player (or Player_Bunny), on February 11, 2024. It says it has new data-stealing capabilities, a reduced payload size, and improved keylogging.
BunnyLoader was first documented by Zscaler ThreatLabz in September 2023. Researchers had described it as malware-as-a-service (MaaS) for collecting credentials and facilitating cryptocurrency theft.
See also: Linux malware AcidPour targets Ukraine
Since then, many new variants of the malware have been released with the aim of improving it and avoiding tools .
The third generation of BunnyLoader incorporates new denial-of-service (DoS) capabilities for HTTP flood attacks and separates the stealer, clipper, keylogger and DoS modules into separate binaries.
“ BunnyLoader operators can choose to deploy these modules or use BunnyLoader’s built-in commands to load the malware of their choice ,” explained Palo Alto Networks Unit 42 researchers .
The infection chains that BunnyLoader provides have also become progressively more sophisticated.
See also: AZORult malware spreads via fake Google websites
“In the ever-changing MaaS landscape, BunnyLoader continues to evolve, demonstrating the need for threat to frequently change methods to evade detection,” the researchers said.
However, these developments show that users must also be constantly vigilant and take measures to protect themselves.

What are the best methods for protecting against info-stealer malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
Installing reliable security software is another key method of protecting against info-stealer malware, such as BunnyLoader. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing.
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
See also: MacOS info-stealer malware evades detection by XProtect
Using strong passwords and changing them regularly can protect your data from theft. Also, using a password manager can help manage and secure your passwords.
Finally, careful interaction with emails and attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware (e.g. BunnyLoader malware).
Source: thehackernews.com
