A new group of hackers, calling themselves “Marko Polo,” appears to be behind a massive info-stealer malware distribution, which includes thirty campaigns with different targets.

Attackers are using a variety of distribution channels, including malicious advertising, spear-phishing , and impersonation to spread at least 50 malware payloads, including AMOS, Stealc, and Rhadamanthys.
According to Recorded Future's Insikt Group, the malware campaign has affected thousands of people (crypto users, gamers, and many others).
Looking at Marko Polo's activity, researchers believe that tens of thousands of devices may have been compromised worldwide. This means that the info-stealer malware may have stolen millions of personal and corporate data.
See also: Ukrainian administrator of Raccoon Infostealer Malware arrested
“This entails significant risks both for the private lives of consumers and for business continuity. Also, it is almost certain that this operation generates illegal revenues of millions of dollars, highlighting the negative economic impacts of such criminal activities in cyberspace“.
Insikt Group reports that Marko Polo hackers rely primarily on spear-phishing, sending messages to victims on social media platforms. They mainly target cryptocurrency influencers, gamers, software developers, and other individuals who are likely to handle valuable data or assets.
Victims are tricked into downloading malicious software, believing they are opening files related to legitimate jobs or collaborations for projects.
Some of the companies impersonated to convince victims of their credibility include Fortnite (gaming), Party Icon (gaming), RuneScape (gaming), Rise Online World (gaming), Zoom (productivity), and PeerMe (cryptocurrency).
The Marko Polo hackers also use their own brands that are not related to existing projects, such as Vortax/Vorion and VDeck (meeting software), Wasper and PDFUnity (collaboration platforms), SpectraRoom (crypto communications) and NightVerse (web3 game).
In some cases, victims are directed to a website for fake virtual meetings, messages and gaming applications, which are used to install the info-stealer malware. Other campaigns distribute the malicious software via executable files (.exe or .dmg) in torrent files.
See also: Ransomware groups are using more infostealers
The new campaign targets both Windows and macOS
The tools of the hackers Marko Polo are many and allow them to carry out various attacks on different platforms and in different ways.
On Windows, HijackLoader is used to deliver Stealc, which steals data from browsers and crypto wallet applications. Also distributed is Rhadamanthys, a more specialized theft program that targets a wide range of applications and data types.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
On macOS systems, hackers Marko Polo develop Atomic (“AMOS”), which allows the theft of various data stored in web browsers.

Protection from info-stealer malware
Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities. The malware used by the Marko Polo team is detected by the most modern antivirus software. Therefore, always scan downloaded files before executing them to check that everything is fine.
See also: ESET Report: Infostealers use AI to extort money
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.
It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.bleepingcomputer.com
