Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » NS-STEALER uses Discord bot to steal your secrets from popular browsers
    Cyber Security

    NS-STEALER uses Discord bot to steal your secrets from popular browsers

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 22, 2024Editorial DepartmentBrowser Security/Internet Threats

    Cybersecurity researchers have discovered a new “sophisticated” Java-based information-stealing program that uses Discord bots to steal sensitive data from infected hosts.

    The malware is called NS-StealerTrellix security researcher Gurumoorthi Ramanathan said in an analysis report released last week that it is spread through ZIP files disguised as cracking software.

    The ZIP file contains a malicious Windows shortcut file (“Loader GAYve”), which acts as a pipeline to deploy the malicious JAR file. The file first creates a file named “NS-<11-digit_random_number>” folder to store the collected data.

    Internet security

    The malware then stores screenshots, cookies, credentials and autofill data, system information, installed programs lists, Discord tokens, Steam and Telegram session data stolen from more than two dozen web browsers into this folder . The captured information is then leaked to the Discord Bot channel.

    “Given the highly sophisticated functionality of collecting sensitive information and using X509Certificate to support authentication, this malware can quickly steal information from the victim’s system through: [Java Runtime Environment]Ramanathan said.

    “Discord bot channels are also cost-effective as event listeners for receiving leaked material.”

    This development comes as the threat actor behind the Chaes (also known as Chae$) malware releases an update (version 4.1) to its information-stealing program, improving its Chronod module, which is responsible for stealing input in web browsers. login credentials and intercept crypto transactions.

    Internet security

    According to Morphisec, the infection chain that spreads the malware uses a legal-themed email lure written in Portuguese to trick recipients into clicking on a fake link that deploys a malicious installer to launch Chae$ 4.1.

    But interestingly, the developers also left information to security researcher Arnold Osipov – who has conducted extensive analysis of Chaes in the past – that could help them improve the “software” directly in the source code. Express thankfulness.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.