New Stealit Malware Exploits Node.js Extensions to Target Windows Systems
Security researchers have identified a new campaign of the Stealit malware, which exploits an experimental Node.js feature to infect Windows systems.
Security researchers have identified a new campaign of the Stealit malware, which exploits an experimental Node.js feature to infect Windows systems.
According to a report from FortiGuard Labs, threat actors are utilizing Node.js's Single Executable Application (SEA) functionality to package and distribute their malicious payloads. This marks a shift from previous Stealit versions that used the Electron framework.
The malware is distributed through file-sharing platforms like Mediafire and Discord, disguised as installers for popular games and VPN software. Security analysts observed a spike in detections of a Visual Basic script used by the malware to establish persistence on compromised machines.
Stealit Malware Exploits Node.js Extensions
The operators behind Stealit operate a sophisticated Malware-as-a-Service (MaaS) business, promoting their product on a public-facing website. The site offers Stealit as a "professional data extraction solution" with various subscription plans.
A lifetime license for the Windows version at approximately $500. The Android variant priced at around $2,000.
Stealit includes capabilities typical of Remote Access Trojans (RAT), such as remote file access, webcam hijacking, live screen monitoring, and a ransomware deployment module.
The latest version of Stealit employs multiple layers of obfuscation and anti-analysis features designed to evade detection. Upon execution, the malware conducts checks to determine if it is running within a virtual machine or security analysis environment, inspecting system memory, CPU core count, hostnames, running processes, and registry keys.
Security researchers have identified a new campaign of the Stealit malware, which exploits an experimental Node.js feature to infect Windows systems.
If any security research artifacts are detected, the malware terminates execution, presenting a fake error message.
After bypassing security checks, the malware downloads components from its command-and-control (C2) server to execute data theft. It adds its installation directories to the Windows Defender exclusion list to avoid detection by endpoint security products.
save_data.exe : Extracts sensitive information from Chromium-based browsers using ChromElevator. stats_db.exe : Steals data from applications like Telegram, WhatsApp, Steam, Epic Games, and cryptocurrency wallets.
Type SHA256 / URL
File 554b318790ad91e330dced927c92974d6c77364ceddfb8c2a2c830d8b58e203c
File aa8f0988f1416f6e449b036d5bd1624b793b71d62889afdc4983ee21a1e7ca87
File 5ea27a10c63d0bbd04dbea5ec08fe0524e794c74d89f92ac6694cfd8df786b1f
File 083c4e0ffdc9edf0d93655ee4d665c838d2a5431b8064242d93a545bd9ad761b
URL https[:]//iloveanimals[.]shop/
URL https[:]//www[.]mediafire[.]com/file/9ni7pgjxuw8pc6h/ShaderSetup.rar/file
Based on reporting by GBHackers.
