$type=sticky$count=4$viewall=hide$show=/label/Mobile$label=hide$mt=hide$rm=hide

$type=grid$meta=0$readmore=0$snippet=0$col=4$show=/label/News$label=hide$viewall=hide

$type=slider$snippet=hide$cate=0$h=400$va=0$rm=0$author=hide$comment=hide$date=hide$show=home

SPOTLIGHT$type=two$meta=0$readmore=0$snippet=0$count=6$viewall=hide$show=home

Vega Stealer Malware Said to Steal Saved Credentials From Chrome, Firefox Browsers

Researchers have discovered a malware called Vega Stealer that is said to have been designed to harvest financial data from the saved cr...


Researchers have discovered a malware called Vega Stealer that is said to have been designed to harvest financial data from the saved credentials of Google Chrome and Mozilla Firefox browsers. The malware is another variant of August Stealer crypto-malware that steals credentials, sensitive documents, cryptocurrency wallets, and other details stored in the two browsers. As of now, the Vega Stealer is only being used in small phishing campaigns, but researchers believe that the malware can potentially result in major organisational level attacks.

According to researchers from Proofpoint, a campaign was found to be targeting Marketing/ Advertising/ Public Relations, and Retail/ Manufacturing industries with a new malware. On May 8 this year, the researchers observed and blocked a low-volume email campaign with subjects such as 'Online store developer required'. The email contains an attachment called 'brief.doc', which contains malicious macros that download the Vega Stealer payload. They said that while some emails were sent to individuals, others were sent to distribution lists including 'info@', 'clientservice@', and 'publicaffairs@' at the targeted domains. It is an approach that has the effect of amplifying the number of potential victims.

The Vega Stealer ransomware allegedly takes special aim at those in the marketing, advertising, public relations, and retail/ manufacturing industries. Once the document is downloaded and opened, a two-step download process is initiated. "The first request executed by the document retrieves an obfuscated JScript/PowerShell script. The execution of the resulting PowerShell script creates the second request, which in turn downloads the executable payload of Vega Stealer," the report said. It added, "The payload is saved to the victim machine in the user's "Music" directory with a filename of 'ljoyoxu.pkzip'. Once this file is downloaded and saved, it is executed automatically via the command line."

Vega Stealer is written in .NET and aims to steal saved credentials such as passwords, saved credit cards, profiles, and cookies, and payment information in Google Chrome. And, in the Firefox browser, the malware harvests specific files - 'key3.db,' 'key4.db,' 'logins.json,' and 'cookies.sqlite' - which store different passwords and keys.

Vega Stealer keeps on working, and takes a screenshot of the infected PC and scans for any files on the system ending in .doc, .docx, .txt, .rtf, .xls, .xlsx, or .pdf for exfiltration.

The researchers claim that the document macro and URLs involved in the campaign suggest that the same threat actor responsible for campaigns spreading financial malware. They could not attribute Vega Stealer to any specific group, it was able to associate this malware with other types now being used. They said that the malicious macro is available for sale and threat actors are using it by pushing the Emotet banking trojan. Meanwhile, the URL patterns from which the macro retrieves the payload are the same as those used by an actor who distributes the Ursnif banking trojan, which often downloads secondary payloads such as Nymaim, Gootkit, or IcedID, the researchers said.

While Vega Stealer is not the most complex malware in circulation today, it does demonstrate the flexibility of malware, authors, and actors to achieve criminal objectives.

In order to be safe, Ankush Johar, Director at Infosec Ventures, said in a press statement, "Organisations should take cyber awareness seriously and make sure that they train their consumers and employees with what malicious hackers can do and how to stay safe from these attacks. One compromised system is sufficient to jeopardize the security of the entire network connected with that system."

COMMENTS

Name

#JioFibernet,1,American Kingpin,1,Android,159,Apple,60,Apps,103,Asus,4,Finney,1,FrontPost,107,Gadgets,20,Gaming,10,Gionee,1,Google,46,Honor,2,How-To,18,Htc,12,Huawei,20,Intex,1,iPhone,34,Jio,14,Lenovo,2,LG,15,Micromax,4,Microsoft,40,Mobile,269,Motorola,23,News,451,Nokia,36,OnePlus,24,Oppo,7,Panasonic,1,pcs,33,Privacy,1,Realme,1,Reviews,29,Samsung,48,Science,10,Security,2,Silk Road,1,Sony,7,Specs,32,Spotlight,82,Technology,4,Trending,203,VIvo,5,Windows,24,Xiaomi,58,Zedd,2,
ltr
item
The Technoverse: Vega Stealer Malware Said to Steal Saved Credentials From Chrome, Firefox Browsers
Vega Stealer Malware Said to Steal Saved Credentials From Chrome, Firefox Browsers
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDWuB7BD5oWDHfkrc5iXHYWoHu2CwjCRwvM1BfwwJ_4b6_0UAEWhjJDKbzo_5v5zpHG2V_zA5mLejV58rdAZYP9D_FzWlm3i1Q4R7z6kGwS-n7yoU9JJKzkwDo-70V14ILf5vDP8V9OnLU/s1600/firefox-chrome.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDWuB7BD5oWDHfkrc5iXHYWoHu2CwjCRwvM1BfwwJ_4b6_0UAEWhjJDKbzo_5v5zpHG2V_zA5mLejV58rdAZYP9D_FzWlm3i1Q4R7z6kGwS-n7yoU9JJKzkwDo-70V14ILf5vDP8V9OnLU/s72-c/firefox-chrome.jpg
The Technoverse
https://the-technoverse.blogspot.com/2018/05/vega-stealer-malware-said-to-steal.html
https://the-technoverse.blogspot.com/
https://the-technoverse.blogspot.com/
https://the-technoverse.blogspot.com/2018/05/vega-stealer-malware-said-to-steal.html
true
8813924560497705682
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy