Security researchers have studied the Byakugan info-stealer malware, which was initially detected in January, and are now providing more details about its operation and characteristics.

While investigating a recent malware distribution campaign via malicious PDFs , the FortiGuard team discovered additional information about the malware.
According to the researchers, the Byakugan's modus operandi bears similarities to previously discovered malware. The info-stealer disguises itself as an Adobe Reader, in a Portuguese PDF, and invites users to download and run it on their device.
See also: Malicious ads distribute info-stealer malware on MacOS
The PDF prompts victims to click on a hidden link, which gradually leads them to a downloader. This downloader, called “require.exe”, along with a legitimate installer, infiltrates the system. A DLL is then downloaded, which is executed via DLL-hijacking to retrieve the main operating system, “chrome.exe”.
The core module of the Byakugan malware is retrieved from a designated command-and-control (C2) server, which can serve as the attacker's control panel.
By examining the malware's source code, researchers found that its functions are diverse. These functions include monitoring screen, taking screenshots, cryptocurrency mining, keystroke logging, file manipulation, and stealing browser information . In addition, the Byakugan malware can adjust mining activities based on system usage , avoiding performance impact during high-demand tasks.
See also: Snake info-stealer malware: Distributed via Facebook messages
Researchers also observed that the developers of the Byakugan malware have incorporated anti-analysis measures and ensured persistence by configuring the task scheduler to run at system. This dual approach of incorporating both legitimate and malicious components complicates analysis, making accurate detection difficult.
“This approach increases the difficulty of analysis. However, the downloaded files provided crucial details about how the Byakugan works, which helped us analyze the malicious modules“.

Protection from info-stealer malware
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus equipped with advanced analysis capabilities.
It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.
See also: Info-stealer malware targets the online gaming community
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Also, don't forget to use firewalls and monitor network traffic , which will help you immediately identify suspicious activity.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.infosecurity-magazine.com
