PryntStealerマルウェアはダークウェブでのみ販売されています $100 月額
Cybersecurity specialists from Cyble 発見した a new information-stealing malware called Prynt Stealer. The malware has a wide range of capabilities and comes with additional keylogger and clipper modules.
プリントスティーラー is advertised as a solution to compromise a wide variety of browsers, instant messengers and gaming applications, and it is also capable of carrying out direct financial attacks.
Prynt Stealer is a subscription service and the authors charge $100/month, $200/quarter, or $700/year, and offer a lifetime license for $900.
ところで, if you are interested in the darknet criminal life, you might like our article: のダークネットサイト REvil グループは再び働いています: ロシア人にサイバー犯罪者を野生に解放させます? or you might be interested in this information: RedLineスティーラー マルウェアは、2つの主要な市場におけるクレデンシャルの主なソースです.
又, buyers can use the constructor to create their own, compact and hard-to-detect version of the malware that can be used in targeted attacks.
Cyble analysts write that Prynt Stealer was created with an emphasis on stealth and uses binary obfuscation and string encryption using Rijndael. 加えて, all communications with the management servers are encrypted using AES256, and the AppData folder (and subfolders) needed to temporarily store stolen data is hidden.
Once on the victim’s machine, Prynt Stealer scans all disks on the host and steals documents, database files, source code, and image files smaller than 5120 bytes (5 KB).
その後, the malware switches to browsers based on Chrome, Firefox and MS Edge, stealing autofill data, credentials, bank card information, search history and cookies. At this stage, the malware uses ScanData() to search browser data for keywords related to banks, cryptocurrencies, and porn sites, and steals what it finds if information is found.
After Prynt Stealer attacks messengers, 含む 不和, Pidgin そして 電報, and steals Discord tokens if they are in the system. Game application authorization files, game save files and other valuable data from Ubisoft Uplay, 蒸気 そして マインクラフト are also stolen.
最終的には, the malware queries the registry to find the data of cryptocurrency wallets such as Zcash, Armory, Bytecoin, Jaxx, イーサリアム, AtomicWallet, Guarda そして Coinomi, and also steals information from FileZilla, OpenVPN, NordVPN and ProtonVPN by copying the corresponding credentials to the one mentioned above. subfolder in AppData.
The data transfer itself is carried out using a Telegram bot, which uses an encrypted network connection to upload the dump to a remote server.
上記のように, in addition to these functions, the malware is equipped with keylogger modules (to intercept keystrokes) and a clipper (tracks and replaces cryptocurrency addresses in the clipboard).