Shuyal Stealer Malware Exploits 19 Browsers to Steal Logins
Shuyal Stealer is a newly identified infostealer malware that extends beyond typical browser-targeted threats.
Shuyal Stealer is a newly identified infostealer malware that extends beyond typical browser-targeted threats.
Unlike other variants that focus on popular browsers such as Chrome and Edge, Shuyal targets 19 different browsers, significantly enhancing its data-harvesting capabilities.
In addition to stealing browser-stored credentials, Shuyal conducts extensive system reconnaissance, gathering detailed information on disk drives, input peripherals, and display configurations.
It also captures screenshots and clipboard contents, collects Discord tokens, and utilizes a Telegram bot infrastructure for data exfiltration, making it an efficient and stealthy tool.
The malware is delivered as a 64-bit C++ executable compiled into an obfuscated binary. Its integrity hashes are MD5: 9523086ab1c3ab505f3dfd170672af1e and SHA-256: 8bbeafcc91a43936ae8a91de31795842cd93d2d8be3f72ce5c6ed27a08cdc092.
Upon execution, Shuyal uses Windows Management Instrumentation (WMI) commands to extract detailed hardware information, tailoring its tactics to each system.
Shuyal Stealer is a newly identified infostealer malware that extends beyond typical browser-targeted threats.
Credential harvesting is performed through targeted SQL queries against browser-stored SQLite databases, retrieving saved credentials from various browsers including Chrome, Edge, Tor, Brave, and Opera, among others.
Shuyal also captures clipboard text, saves screenshots, and extracts Discord tokens from standard client installations.
The infection chain starts with a malicious executable that creates a "runtime" directory to stage collected data. A PowerShell script compresses this directory into a ‘runtime.zip’ archive, which is exfiltrated using Telegram’s Bot API.
After exfiltration, the malware deletes traces using a batch file, minimizing forensic footprints. Shuyal terminates task manager processes to prevent inspection and achieves persistence by copying itself into the Windows Startup folder.
Removing Shuyal Stealer involves Safe Mode intervention and specialized tools. It is recommended to reboot into Safe Mode with Networking and use antivirus software to identify and remove the threat.
Manual removal includes deleting malicious files from the Startup folder and restoring registry values. Monitoring PowerShell activities can aid in detecting and blocking exfiltration attempts.
Shuyal Stealer poses significant risks to user privacy and organizational security through its broad targeting, extensive system profiling, and stealthy data exfiltration methods.
Based on reporting by GBHackers.
