Mars Stealer

General News

Summary

Thanks to an analysis performed by the security researcher @3xp0rt, it was determined that, for the most part, the Mars Stealer is a redesign of a similar malware named Oski that had its development shut down in the middle of 2020 abruptly. Afterward, the Mars Stealer will extract data from the most popular Web browsers, 2FA (Two-Factor Authentication) applications, crypto extensions and crypto-wallets. Among the affected app lications are Chrome, Internet Explorer, Edge (Chromium Version), Opera, Sputnik Browser, Vivaldi, Brave, Firefox, Authenticator, GAuth Authenticator, MetaMAsk, Binance, Coinbase Wallet, Coinomi, Bitcoin Core and its derivatives, Ethereum, Electrum and many more. To make detection more difficult, the malware utilizes routines tasked with hiding its API calls, as well as strong encryption with a combination of RC4 and Base64. For example, if the language ID of the breached device matches any of the following countries - Russia, Azerbaijan, Belarus, Uzbekistan, and Kazakhstan, the Mars Stealer will terminate its execution.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M