Incidents involving infostealers have more than doubled in Q1 2023 compared with the same time period last year, and are attacking three major platforms: Windows, Linux and the macOS.In a study released July 26 by Uptycs, the researchers said most of these malware authors are using Telegram as a platform for command-and-control (C2) and data exfiltration.Infostealer malware targets victims by stealing sensitive information that can include passwords, login credentials and other personal data. After collecting the data, the stealer sends it to the threat actor’s C2 system.In examining the dark web, Uptycs found that RedLine has become the prominent infostealer in the marketplace with a 56% market share, followed by Raccoon (15%) and the RecordBreaker stealer. Newcomer Meta (11%), Vidar (10%), Cryptbot, and AZORult are additional information stealers used in 2022.Infostealers are primarily sold on cybercrime forums. Along with being sold on Telegram, their logs are also sold on other instant messaging platforms such as Discord. Stealer and log prices generally range between $200 to $300 a month, or around $1,000 for a lifetime subscriptionAccording to Uptycs, one of the most prominent 2022 attacks targeted Uber’s systems. A threat actor used the Racoon infostealer to break through the ride-share company’s defenses, sending a fake two-factor authentication notification urging victims to click a link to verify a request. Once a user’s system was compromised, the attacker used the company’s VPN to access internal network resources. After gaining access to the Uber’s access management service, they used it to escalate account privileges and claimed access to several Uber resources, including AWS, Duo, GSuite, OneLogin, Slack, VMware and Windows.
Malware, Data Security, Privacy
Infostealer incidents more than doubled in Q1 2023

Criminals are targeting Windows, Linux and the macOS platforms with infostealer malware, according to Uptycs research. (Adobe Stock Images)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



