Rewterz Threat Alert – BluStealer Infostealer – Active IOCs
Severity
Medium
Analysis Summary
BluStealer is a new infostealer identified in the later half of 2021. It’s finctionality include the ability to steal login credentials, cryptocurrency, credit card information, and more. It is delivered through a phishing email containing malicious email attachments. A sample of this techniques is seen going around where the sender has crafted a fake DHL letter to scam the victims.
Once the malicious attachment is opened and executed, the Operating system of the victim is infected and BluStealer is distributed within the infected system. Other modes of distribution include PDF Documents, Microsoft Office Files, JavaScript files, or zipped and archived files. Blustealer can also log keyboard inputs to steal data. It can steal credentials stored on web browsers like chrome, firefox, and others and also extract database files from online wallets like Bytecoin, Electrum, Guarda, and others.