<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Stealerium Malware &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/stealerium-malware/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Sun, 12 Feb 2023 21:58:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>Stealerium Malware &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cybercriminals spread malware through fake job proposals</title>
		<link>https://bitfinance.news/en/cybercriminals-spread-malware-through-fake-job-proposals/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Tue, 14 Feb 2023 19:00:35 +0000</pubDate>
				<category><![CDATA[Cryptocurrencies]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Crypto Industry Jobs]]></category>
		<category><![CDATA[Crypto Industry Professionals]]></category>
		<category><![CDATA[cyber criminals]]></category>
		<category><![CDATA[Eastern Europe]]></category>
		<category><![CDATA[Fake Interview Offers]]></category>
		<category><![CDATA[Payload]]></category>
		<category><![CDATA[Stealerium Malware]]></category>
		<category><![CDATA[victims]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=91095</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="800" src="https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ciberdelincuentes propagan malware a través de falsas propuestas de empleo" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash.jpg 1200w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-1024x683.jpg 1024w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-768x512.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>A campaign run by Russian threat actors focuses on sending fraudulent emails that integrate &#8216;malware&#8217; with alleged job offers and target professionals in the cryptocurrency industry. Trend Micro researchers have analyzed the activity of this group of cybercriminals, who have managed to infect several computers with a modified version of the Stealerium malware called Enigma. [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/cybercriminals-spread-malware-through-fake-job-proposals/">Cybercriminals spread malware through fake job proposals</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="800" src="https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ciberdelincuentes propagan malware a través de falsas propuestas de empleo" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash.jpg 1200w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-1024x683.jpg 1024w, https://bitfinance.news/wp-content/uploads/2023/02/ed-hardie-Y5PSyMm8nMk-unsplash-768x512.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p style="text-align: justify;">A campaign run by Russian threat actors focuses on sending <strong>fraudulent emails</strong> that integrate &#8216;malware&#8217; with <strong>alleged job offers</strong> and target professionals in the <strong>cryptocurrency industry.</strong></p>
<p style="text-align: justify;"><em>Trend Micro</em> researchers have analyzed the activity of this group of cybercriminals, who have managed to infect several computers with a modified version of the <strong>Stealerium malware called Enigma.</strong></p>
<p style="text-align: justify;">Stealerium is an information<strong> stealer built on the C# programming language t</strong>hat sends logs of stolen information to a server controlled by the threat actors themselves. In addition to getting hold of this type of information, you can take <strong>screenshots and even record keystrokes.</strong></p>
<p style="text-align: justify;">In this case, <strong>Enigma has used fake job offers and interviews</strong> targeting <strong>Eastern European</strong> cryptocurrency professionals with an infection chain that starts with a <strong>malicious RAR file</strong> distributed via <strong>social media and email.</strong></p>
<p style="text-align: justify;">The file received by the victims contains <strong>two documents</strong>: one in which the <strong>interview</strong> questions are named <strong>(document in .txt format)</strong> and another in which the conditions of the<strong> employment</strong> position are presumably included<strong> (.word.exe).</strong></p>
<p style="text-align: justify;">The <strong>interview file contains questions in Cyrillic,</strong> the writing system used to legitimize the <strong>fraudulent document.</strong> On the other hand, the vacancy conditions file contains the first load of Enigma malware. Its goal is to download and unzip malicious software, which is installed on the device in various parts or payloads.</p>
<p style="text-align: justify;">
<h2 style="text-align: justify;">Cybercriminals steal user data</h2>
<p>&nbsp;</p>
<p style="text-align: justify;">According to the <em>Trend Micro</em> study, Enigma uses <strong>two servers.</strong> The first uses the <strong>Telegram</strong> application, through a channel controlled by the attacker, to deliver payloads and send commands. The second one is used for <strong>DevOps</strong> and to complete the registration of the malicious payload, whose main objective is to disable the Microsoft Defender security system, by deploying a malicious Intel kernel mode driver and exploiting a vulnerability in it, identified as CVE-2015. -2291.</p>
<p style="text-align: justify;">This driver gap allows commands to be executed with kernel privileges, so threat actors are able to <strong>disable</strong> <strong>Microsoft Defender</strong> before the malicious software downloads and runs the third payload.</p>
<p style="text-align: justify;">Once integrated into the infected device&#8217;s system, Enigma collects and steals system and user information, including passwords for various web browsers and applications such as <strong>Google Chrome, Microsoft Edge, Signal, Telegram, OpenVPN, and Microsoft Outlook, among others.</strong> others.</p>
<p style="text-align: justify;">Once this data is collected, it is filtered and compressed into a <strong>ZIP file</strong> to be sent to the threat actor itself through the <strong>Telegram messaging application.</strong> These movements are registered in DevOps to continue developing, profiling and improving the performance of the &#8216;malware&#8217;.</p>
<p style="text-align: justify;">Source: dpa</p>
<p style="text-align: justify;"><em>(Reference image source: Ed Hardie, Unsplash)</em></p>
<p style="text-align: justify;"><em>Visit our news channel on </em><a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener"><strong><em>Google News</em></strong></a><em> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><strong><em>Twitter</em></strong></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><strong><em>Instagram</em></strong></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/cybercriminals-spread-malware-through-fake-job-proposals/">Cybercriminals spread malware through fake job proposals</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
