Infostealer
WhiteSnake Stealer
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and crypto wallets.
WhiteSnake Stealer is a Windows infostealer.
Background
First seen in February 2022, WhiteSnake Stealer is an advanced .NET information stealer aimed at browsers, installed applications, and cryptocurrency wallets.
Its builder can output payloads in a wide variety of formats, including EXE, SCR, COM, CMD, BAT, VBS, PIF, WSF, .hta, MSI, PY, DOC, DOCM, XLS, XLL, XLSM. A few of these, such as python and bash, let the malware execute on Linux hosts.
The stealer offers two execution modes:
- Non-resident - it deletes itself once it has finished running
- Resident - it keeps beaconing to the C2, which may reside on the TOR network
Beyond data theft, WhiteSnake Stealer can collect system information, run remote commands, propagate via USB drives, and carry out keylogging, file management, and webcam capture.
Source: Malpedia (Fraunhofer FKIE).