Rewterz
Rewterz Threat Alert – Lokibot Malware – Active IOCs
June 14, 2021
Rewterz
BackdoorDiplomacy APT Group Actively Targeting Middle East, Asia, And Africa – Active IOCs
June 14, 2021

Rewterz Threat Alert – Oski Data Stealer Malware – Active IOCs

Severity

High

Analysis Summary

An emergent and effective data-harvesting tool dubbed Oski is proliferating in North America and China, stealing online account credentials, credit card numbers, crypto wallet accounts, and more. The malware is still in its developing phase but packs a punch with its capabilities. Oski C2’s dashboard revealed that Oski’s theft tactics involve extracting credentials using man-in-the-browser (MitB) attacks by hooking the browser processes using DLL injection, It also extracts credentials from the registry, passwords from the browser SQLite database, and stored session cookies of all stripes, including crypto-wallet cookies from Bitcoin Core, Ethereum, Monero, Litecoin, and others.

Impact

  • Credential theft
  • Information disclosure

Indicators of Compromise

MD5

  • 3b014082a0ebcbc1d47ced56f1404aab
  • 485609c090f936b274f0f53cb85cab12
  • 587019a76119966735b206753a44b53c

SHA-256

  • 0d0e571bf5bc85d8685228a91bc7e4d087df034ee1a089e24b57057e5767b9c4
  • bf5b613e142655ffc08aa2890da9de4bd798c1de4d163f2ea8f2d830ddee8984
  • d7c1e5987974c0fd1d54836719e24c6223e4c7af14d6869f7e1cb9d94c7a83ea
  • fb30ae8d4bcce71593ae5da2277634ad9ccf2964f1dc7f9997872b498753aa74

SHA1

  • e9160714ad08b206204d647a245f89e73459e8b7
  • bf14df7741ff532e09d45f7249609d9c53374fc2
  • d3eff2720f7222908dab81df323a4e772f973e64

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders