Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV

10/2/2019
06:00 AM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Masad Stealer Uses Telegram to Send Its Control Messages to Waiting Bots

Juniper Threat Labs has discovered a new Trojan-delivered spyware that uses Telegram to exfiltrate stolen information.

Juniper Threat Labs has discovered a new Trojan-delivered spyware that uses Telegram to exfiltrate stolen information. Using Telegram for a Command and Control (C&C) channel gives the malware some anonymity. Telegram is a legitimate messaging application that boasts of 200 million monthly active users.

Jupiter says the malware is being advertised on black market forums as "Masad Clipper and Stealer." It starts with a free version and goes up to versions asking up to $85, with each tier of the malware offering different features.

Jupiter says that the malware steals browser data, which may then give up usernames, passwords and credit card information. Masad Stealer also automatically replaces cryptocurrency wallets from the clipboard with its own, so it does outright stealing as part of its nefarious activities.

The malware is made up of Autoit scripts and then it is compiled into a Windows executable. Jupiter saw most samples were about 1.5 MiB in size. But Masad Stealer can be found in larger executables since it has been bundled into other software.

Once started up, it drops itself in %APPDATA%\folder_name}\{file_name}, where folder_name and file_name have been defined in the binary. Examples might be names like amd64_usbhub3.inf.resources and ws2_32.exe, respectively. To gain persistence, Masad Stealer creates a scheduled task that will start itself every one minute.

It goes after certain information like cryptocurrency wallets, PC and system information, credit card browser data, browser passwords, desktop files, browser cookies, Steam files, AutoFill browser fields, Discord and Telegram data and FileZilla files.

\r\nIt zips all of these into a file and then using a hardcoded bot token (a way to communicate with the Command and Control bot) it will send this zip file using the sendDocument API.

\r\nThere is also a function that replaces wallets on the clipboard, as soon as it matches a particular configuration. The malware searches for wallets containing Monero, Bitcoin Cash, Litecoin, Neo, Web Money, ADA, ZCASH, DogeCoin, Stratis, QIWI Pay, Bicond, Waves, Reddcoin, Qtum, Payeer, Bytecoin, Bitcoin, Black Coin, VIA, Steam Trade Link, Bitcoin Gold, Emercoin, Lisk, Ethereum, Dash, Ripple and Yandex Money.

Based on Jupiter's telemetry, Masad Stealer's main distribution vectors will disguise it as a legitimate tool or may bundle it into third party tools. It has tried to pass itself off as ProxySwitcher, CCleaner, Utilman, Netsh and Whoami.

Since it has been distributed on forums, there are many variants of this malware in the wild. Each variant family may be assumed to control its own bot.

There is at least one dedicated website, (masadproject[.]life), in existence that promotes the sale of Masad Stealer. Ironically, the developers have also created a Telegram group for their potential clients which may even offer tech support. At time of writing, Juniper says that this group has more than 300 members.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21742
PUBLISHED: 2021-09-25
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
CVE-2020-20508
PUBLISHED: 2021-09-24
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
CVE-2020-20514
PUBLISHED: 2021-09-24
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
CVE-2016-6555
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in ver...
CVE-2016-6556
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI views the data. This iss...