DeerStealer Malware Deployed Through Exploitation of Windows Run Prompt by Threat Actors
The eSentire's Threat Response Unit (TRU) has identified a series of malicious campaigns in May 2025 involving the deployment of DeerStealer malware, also known as XFiles Spyware, via the HijackLoader malware loader.
The eSentire's Threat Response Unit (TRU) has identified a series of malicious campaigns in May 2025 involving the deployment of DeerStealer malware, also known as XFiles Spyware, via the HijackLoader malware loader.
The DeerStealer malware is designed to extract sensitive data, including cryptocurrency wallets, browser credentials, VPN details, and instant messaging information.
The attack chain begins with a phishing technique called ClickFix, which tricks users into executing a malicious PowerShell command via the Windows Run Prompt. This leads to the download of DeerStealer as the final payload.
The attack initiates with a redirection to a ClickFix page, prompting users to run an encoded PowerShell script. This script downloads a malicious Microsoft Installer (MSI) file, "now.msi," using curl.exe.
This method exploits legitimate system features, highlighting the evolving tactics of cybercriminals in bypassing traditional security measures.
The attack initiates with a redirection to a ClickFix page, prompting users to run an encoded PowerShell script.
The installer places files into C:\ProgramData and utilizes a legitimate COMODO Internet Security binary to load a tampered version of cmdres.dll. Through a hooked C runtime function, the HijackLoader is initiated. It uses steganography to store encrypted configurations in PNG images.
The loader resolves APIs dynamically and decrypts subsequent stages from embedded files, eventually injecting DeerStealer into processes via module stomping of legitimate binaries like input.dll.
DeerStealer exhibits advanced capabilities, including control flow obfuscation, virtual machine-based string decryption, and encrypted HTTPS communication with command-and-control (C2) servers. It fingerprints victim machines and packages stolen information into logs. It supports clipboard hijacking for over 14 cryptocurrency types and targets over 50 web browsers, as well as desktop applications like Discord, Telegram, FileZilla, and Steam.
The malware is available via a subscription model, with the Premium tier starting at $200 per month and the Professional tier at $3000. It offers features such as Hidden VNC for remote control, custom ClickFix scripts, and bypasses for Windows Defender and SmartScreen. Future expansions include MacOS support, AI integration, and automated crypto balance checking.
The sophisticated use of legitimate tools and obfuscation techniques necessitates enhanced vigilance, robust endpoint protection, and user education to prevent exploitation of system functionalities like the Windows Run Prompt.
Proactive measures are essential to detect and mitigate these complex threats before they compromise critical data.
Based on reporting by GBHackers.
