Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • This New Fileless Malware Hides Shellcode in Windows Event Logs cyber security news
  • BTC Below $40,000 Prior to Wednesday’s Fed Meeting – Market Updates Bitcoin News bitcoin news
  • QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available cyber security news
  • Bitcoin Price Hits Three-Month Low, What’s Driving This? bitcoin news
  • Bitcoin Bears Keep Pushing, Why Upsides Remain Limited bitcoin news
  • Onecoin ‘Crypto Queen’ Ruja Ignatova Listed Among Europe’s Most Wanted – Bitcoin News bitcoin news
  • 7 Key Findings from the 2022 SaaS Security Survey Report cyber security news
  • Bitcoin Long Squeeze Incoming? Funding Rates Surge Up bitcoin news

Experts Detail Saintstealer and Prynt Stealer Info-Stealing Malware Families

Posted on May 10, 2022 By root


Cybersecurity researchers have dissected the inner workings of an information-stealing malware called Saintstealer that’s designed to siphon credentials and system information.

“After execution, the stealer extracts username, passwords, credit card details, etc.,” Cyble researchers said in an analysis last week. “The stealer also steals data from various locations across the system and compresses it in a password-protected ZIP file.”

A 32-bit C# .NET-based executable with the name “saintgang.exe,” Saintstealer is equipped with anti-analysis checks, opting to terminate itself if it’s running either in a sandboxed or virtual environment.

The malware can capture a wide range of information that ranges from taking screenshots to gathering passwords, cookies, and autofill data stored in Chromium-based browsers such as Google Chrome, Opera, Edge, Brave, Vivaldi, and Yandex, among others.

It can also steal Discord multi-factor authentication tokens, files with .txt, .doc, and .docx extensions as well as extract information from VimeWorld, Telegram, and VPN apps like NordVPN, OpenVPN, and ProtonVPN.

Besides transmitting the compressed information to a Telegram channel, the metadata related to the exfiltrated data is sent to a remote command-and-control (C2) server.

What’s more, the IP address linked to the C2 domain — 141.8.197[.]42 — is tied to multiple stealer families such as Nixscare stealer, BloodyStealer, QuasarRAT, Predator stealer, and EchelonStealer.

“Information stealers can be harmful to individuals as well as large organizations,” the researchers said. “If even unsophisticated stealers like Saintstealer gain infrastructural access, it could have devastating effects on the cyberinfrastructure of the targeted organization.”

The disclosure comes as a new infostealer named Prynt Stealer has surfaced in the wild that can also perform keylogging operations and financial theft using a clipper module.

“It can target 30+ Chromium-based browsers, 5+ Firefox-based browsers, and a range of VPN, FTP, messaging, and gaming apps,” Cyble noted last month.

Sold for $100 for a one-month license and $900 for a lifetime subscription, the malware joins a long list of other recently advertised stealers, including Jester, BlackGuard, Mars Stealer, META, FFDroider, and Lightning Stealer.





TheHackersNews/

cyber security news

Post navigation

Previous Post: NASA Partners With Epic Games to Create a Martian Metaverse Simulation – Metaverse Bitcoin News
Next Post: New REvil Samples Indicate Ransomware Gang is Back After Months of Inactivity

Related Posts

  • Microsoft Azure Vulnerability Exposes PostgreSQL Databases to Other Customers cyber security news
  • Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums cyber security news
  • Google to Add Passwordless Authentication Support to Android and Chrome cyber security news
  • QNAP Releases Firmware Patches for 9 New Flaws Affecting NAS Devices cyber security news
  • Thousands of Borrowers’ Data Exposed from ENCollect Debt Collection Service cyber security news
  • New Sysrv Botnet Variant Hijacking Windows and Linux with Crypto Miners cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • Microsoft Mitigates RCE Vulnerability Affecting Azure Synapse and Data Factory cyber security news
  • Telegram Users Can Send and Receive Toncoin Within Messenger Chats – Bitcoin News bitcoin news
  • Bitcoin․com Exchange Market Insights Report for May 2022 – Promoted Bitcoin News bitcoin news
  • Google Forms Web3 Team — Sees Tremendous Potential, Demand for Crypto Tech Support – Featured Bitcoin News bitcoin news
  • Experts Say Ethereum Will Grow 100% To Hit $5,783 By Year-End bitcoin news
  • Tron Is Trading Within Its Triangle Pattern; What Awaits The Coin Next? bitcoin news
  • Central Bank of Chile Studies Issuance of a Digital Currency – Bitcoin News bitcoin news
  • nFLARE Technology Shines a Spotlight on a Unique Model of NFT Marketplaces bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme