HomeSecurityHackers advertise Anivia Stealer on the Dark Web

Hackers advertise Anivia Stealer on the Dark Web

A sophisticated credential-stealing malware dubbed Anivia Stealer has surfaced on underground forums, advertised by a cybercriminal known as ZeroTrace. The malware represents a dangerous evolution in credential-stealing operations, specifically designed to compromise Windows systems from older XP installations to the latest Windows 11 environments.

See also: Qilin Ransomware combines Linux payload with BYOVD exploit

Anivia Stealer

Built using C++17, Anivia Stealer incorporates advanced evasion techniques and extensive data extraction capabilities that pose significant risks to both individual users and corporate networks. The malware's advertising campaign highlights its ability to bypass User Account Control mechanisms through automatic elevation techniques, allowing it to perform privileged operations without triggering security alerts that would normally alert users to suspicious activity.

KrakenLabs researchers have identified the cybercriminal’s promotional efforts on cybercriminal marketplaces, where Anivia Stealer is offered with a subscription model ranging from €120 for one month to €680 for lifetime access . The analysis reveals that the stealer targets an extensive range of sensitive information, including browser credentials, authentication cookies, cryptocurrency wallets, messaging tokens, Local Security Authority credentials, and system screenshots.

See also: The infamous BreachForums returns with a new clean domain

Hackers advertise Anivia Stealer on the Dark Web

The malware maintains encrypted communication channels with its command and control infrastructure and has self-update capabilities to evade detection signatures. Threat intelligence suggests that Anivia Stealer may represent a re-release or fork of the previously identified ZeroTrace Stealer, with GitHub commit history and developer metadata linking both projects to the same malicious actor that has also distributed Raven Stealer.

The key functionality that enables the Anivia Stealer to be effective lies in its implementation of User Account Control bypass. The malware exploits Windows privilege escalation paths to achieve automatic elevation without user interaction, effectively defeating one of the operating system's primary security boundaries. This technique allows the stealer to access protected areas of the system, registry hives containing stored credentials, and memory locations containing authentication secrets that would normally require administrator approval.

See also: Doxxing: How hackers expose hackers – The new trend on the dark web

Hackers advertise Anivia Stealer on the Dark Web

The malware's claim that it requires no external dependencies suggests that it includes all the necessary exploit code within its binary, reducing forensic evidence and simplifying deployment across various target environments while complicating detection efforts by security solutions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS