Skip to content

Infostealer

CopperStealth

According to Trend Micro, CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into explorer.exe and another system process.

CopperStealth is a Windows infostealer operated by Water Orthrus.

Background

Per Trend Micro, CopperStealth begins by dropping and loading a rootkit that subsequently injects its payload into explorer.exe and a second system process, with those injected components handling the retrieval and execution of further tasks. The rootkit additionally restricts access to blocklisted registry keys and prevents specified executables and drivers from launching. Its task module can also fetch and run additional payloads.


Source: Malpedia (Fraunhofer FKIE).