Malware

Maranhão Stealer infostealer spread on pirated software sites

Cyble threat intelligence researchers have uncovered an infostealer campaign spreading the Maranhão Stealer through social engineering websites offering pirated software. The malware, with sophisticated techniques like reflective DLL injection, poses significant cybersecurity risks, based on information published by The Cyber Express.

The Maranhão Stealer campaign uses deceptive websites to distribute malicious files like DerelictSetup.zip, targeting victims for credential theft and cryptocurrency data extraction. The malware, written in Node.js and disguised as an Inno Setup installer, employs advanced tactics to evade detection, establish persistence, and conduct detailed host reconnaissance. Its capabilities include compromising credentials, account hijacking, and deploying further malware within victim environments.

The evolving nature of the Maranhão Stealer highlights the persistent threat posed by sophisticated infostealer campaigns. The malware's ability to adapt, conduct extensive system reconnaissance, and target sensitive data underscores the need for robust cybersecurity measures.

Source: The Cyber Express

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds