Rewterz
Rewterz Threat Alert – Web Skimming (Magecart) attacks Targeted by North Korean Hackers
July 6, 2020
Rewterz
Rewterz Threat Advisory – CVE-2020-9498 – Apache Guacamole code execution vulnerability
July 6, 2020

Rewterz Threat Alert – Taurus Stealer

Severity

High

Analysis Summary

Taurus a new stealer in town that this stealer is capable of stealing passwords, cookies, and autofill forms along with the history of Chromium- and Gecko-based browsers. Taurus can also steal some popular cryptocurrency wallets, commonly used FTP clients credentials, and email clients credentials. This stealer also collects information, such as installed software and system configuration, and sends that information back to the attacker.

The recent campaign is targeting users via phishing emails and luring users to click on malicious attachments.

Infection cycle

Impact

  • Credential theft
  • Cookie theft
  • Exposure of sensitive data 

Indicators of Compromise

MD5

  • 3e08e18ccc55b17eeaeedf3864abca78
  • 221bbac7c895453e973e47f9bce5bfdc

SHA-256

  • b3c75db5faa9b7afe98f081d5654b1e612065020542638e4b09c136b4023fc9c
  • 2fd1db4e9314696c11da1ea15707de31c2e115ffb01c8d3b569a10441ddb6369

SHA1

  • 8bb9a4ddb199c0d5aad1fd7ed2f14ae21dd7d4ca
  • 349ddf1412999df1e51aef5248b15aa7f2af1e02

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.