A recent cybersecurity investigation uncovered a malware distribution campaign called DeerStealer. The malware was disseminated through counterfeit Google Authenticator websites, tricking visitors into downloading the malicious payload hosted on GitHub. Upon execution, the stealer collects system information, encrypts it using XOR encryption, and sends it to a command-and-control server. Analysis suggests DeerStealer might be a rewritten version of the XFiles malware family, sharing some similarities but employing different techniques. Author: AlienVault
Related Tags:
XFiles
DeerStealer
T1587.003
T1497.001
T1059.007
c2
T1204.002
T1518.001
T1071.001
Associated Indicators:
E24C311A64F57FD16FFC98F339D5D537C16851DC54D7BB3DB8778C26CCB5F2D1
D9DB8CDEF549E4AD0E33754D589A4C299E7082C3A0B5EFDEE1A0218A0A1BF1EE
4640D425D8D43A95E903D759183993A87BAFCB9816850EFE57CCFCA4ACE889EC
A6F6175998E96FCECAD5F9B3746DB5CED144AE97C017AD98B2CAA9D0BE8A3CB5
66282239297C60BAD7EEAE274E8A2916CE95AFEB932D3BE64BB615EA2BE1E07A
CB08D8A7BCA589704D20B421768AD01F7C38BE0C3EA11B4B77777E6D0B5E5956
569AC32F692253B8AB7F411FEC83F31ED1F7BE40AC5C4027F41A58073FEF8D7D
B5AB21DDB7CB5BFBEDEE68296A3D98F687E9ACD8EBCC4539F7FD234197DE2227
5E2839553458547A92FFF7348862063B30510E805A550E02D94A89BD8FD0768D