Stealth Soldier Malware
Summary
The cybersecurity community has recently discovered a newly identified custom backdoor called the Stealth Soldier, which has been utilized in a series of sophisticated and specifically targeted espionage campaigns in North Africa. These deceptive binaries serve as a means to deliver the Stealth Soldier malware, while simultaneously displaying a seemingly harmless decoy PDF file to distract the victims. It gathers directory listings and browser credentials, logs keystrokes, records audio from the devices microphone, captures screenshots, uploads files and executes PowerShell commands. Although some of the components of the Stealth Soldier are no longer accessible, analysis has revealed that certain functionalities, such as screen capture and browser credential theft, were inspired by open-source projects available on GitHub. This adaptability implies that the threat actor will likely release updated versions of the malware in the near future, potentially introducing new functionalities and evasive maneuvers to further their surveillance objectives.