Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
July 27, 2022Rewterz Threat Advisory – CVE-2022-36336 – Trend Micro Apex One and Worry-Free Business Security Vulnerability
July 28, 2022Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
July 27, 2022Rewterz Threat Advisory – CVE-2022-36336 – Trend Micro Apex One and Worry-Free Business Security Vulnerability
July 28, 2022Severity
Medium
Analysis Summary
Eternal Stealer – a malware family – can access data from systems like Credential Manager, Vault, and Network Passwords. Browsers, password managers, email clients, messengers, and offline cryptowallets are all targets of this malware (cold wallets). Its creator uses Telegram IM (Instant Messaging) service to market their malicious wares.
Recently some researchers examined the ‘Eternity Project,’ a Tor website that sells a wide range of malware, including stealers, miners, ransomware, and DDoS Bots. Its operators also run a Telegram channel with 500 followers, which is used to share information related to malware updates. Through their Telegram channel, they allow their customers to customize the binary characteristics.
Eternity Stealer
The Stealer module is available for $260 per year as a subscription. It steals sensitive data such as passwords, cookies, credit cards, and crypto-wallets from infected systems. Telegram Bot is used to exfiltrate stolen data.
Eternity Miner & Clipper
Customers can configure the Eternity Miner module with their own Monero pool and AntiVM features for $90 as a yearly subscription. For $110, the Eternity operators also offer the clipper malware, which monitors the clipboard for cryptocurrency wallet addresses and substitutes them with the attackers’ wallet addresses.
Eternity Ransomware & Worm
The Eternity Ransomware costs $490, whilst the Eternity Worm costs $390.
According to researchers,
They have seen a considerable growth in cybercrime via Telegram groups and cybercrime forum, where TAs sell their products without any oversight.
Impact
- Sensitive Information Theft
- Credential Theft
- Crypto wallet Theft
Indicators of Compromise
MD5
- e534402738b11f52fd1991e2c63f816f
SHA-256
- 1c77a07e45b4f3e7f2b756c76df58a9d0f78785aa0f9e154074503398203c695
SHA-1
- 5b166f3f830a9f6a3b2e581321c6541819c31771
Remediation
- Search for IOCs in your environment.
- Block all threat indicators at their respective controls