Skip to content

Infostealer

MicroStealer

According to ANY.RUN, MicroStealer is a rapidly spreading infostealer with low current AV detection that uses a multi stage NSIS, Electron, Node.js, and Java (JAR) delivery chain plus heavy obfuscatio

MicroStealer is a Java infostealer.

Background

ANY.RUN describes MicroStealer as a fast-growing infostealer that currently evades most AV products, relying on a layered delivery chain spanning NSIS, Electron, Node.js, and Java (JAR) along with extensive obfuscation and VM detection to thwart analysis. The malware spreads through hijacked or spoofed accounts and rogue download portals, with concentrations of activity in the US and Germany and a growing focus on the education and telecom industries. After launching, it drops a bundled JRE, gains persistence through a high-privilege ONLOGON scheduled task, and can abuse UAC as well as LSASS token impersonation. Functionally, it grabs browser passwords and session cookies, takes screenshots, drains crypto wallets, takes over and profiles Discord accounts, profiles Steam accounts, and ships compressed data over HTTPS to Discord webhooks and attacker-run servers.


Source: Malpedia (Fraunhofer FKIE).