

Rewterz Threat Advisory – Multiple Apache Linkis Vulnerabilities
April 11, 2023
Rewterz Threat Advisory – Multiple Sophos Web Appliance Vulnerabilities Exploit in the Wild
April 11, 2023
Rewterz Threat Advisory – Multiple Apache Linkis Vulnerabilities
April 11, 2023
Rewterz Threat Advisory – Multiple Sophos Web Appliance Vulnerabilities Exploit in the Wild
April 11, 2023Severity
Medium
Analysis Summary
Eternal Stealer – a malware family – can access data from systems like Credential Manager, Vault, and Network Passwords. Browsers, password managers, email clients, messengers, and offline cryptowallets are all targets of this malware (cold wallets). Its creator uses Telegram IM (Instant Messaging) service to market their malicious wares.
Some researchers examined the ‘Eternity Project,’ a Tor website that sells a wide range of malware, including stealers, miners, ransomware, and DDoS Bots. Its operators also run a Telegram channel with 500 followers, which is used to share information related to malware updates. Through their Telegram channel, they allow their customers to customize the binary characteristics.
Eternity Stealer
The Eternity Stealer is a type of malware that is designed to steal sensitive information, such as usernames, passwords, and other personal data, from infected computers. This particular malware is distributed through phishing emails or malicious websites, and once it infects a system, it can run in the background without the user’s knowledge. The Eternity Stealer can steal information from web browsers, email clients, and other applications that store sensitive information.
The Stealer module is available for $260 per year as a subscription. It steals sensitive data such as passwords, cookies, credit cards, and crypto-wallets from infected systems. Telegram Bot is used to exfiltrate stolen data.
Eternity Miner & Clipper
Customers can configure the Eternity Miner module with their own Monero pool and AntiVM features for $90 as a yearly subscription. For $110, the Eternity operators also offer the clipper malware, which monitors the clipboard for cryptocurrency wallet addresses and substitutes them with the attackers’ wallet addresses.
Eternity Ransomware & Worm
The Eternity Ransomware costs $490, whilst the Eternity Worm costs $390.
According to researchers, they have seen a considerable growth in cybercrime via Telegram groups and cybercrime forum, where TAs sell their products without any oversight.
Impact
- Sensitive Information Theft
- Credential Theft
- Crypto wallet Theft
Indicators of Compromise
MD5
- 5505bbddc971765df496f907b222c2fb
- efe82015c08d9d2b932bd105eacbf6c2
- 0c5f38168a8658fbfc647b0349c3d083
- ba2d4d68e8fe6873810cf5c8236553c1
SHA-256
- a5498ad33354516c8a2affe2de3e3cf515aafb252d5647d0f8c6efe4b46806a4
- 2b4e5d3e94c8ac09ca00108bd0dd3d89fe2a8246176c99b9ff39258deee5988b
- 646d256d38a61cd4e41c7c3392dc7051725353f996d9eeca990d10c5495b858e
- 6c4c86f1896f7dd72471bd4d57b250affdd4e309ea30a389bc98ce4ed11d669b
SHA-1
- de3c8668481fa3dacf2052951d45a9c3a388575d
- 0e0f7ea6e539f1b22ce9814614d2af63e4ba6fb8
- 85c1bfe4e80cecf89d96ce3521e92cf1d7041c23
- 48bc107beaa619d3df830f5b9d999c7ad9507fc0
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Do not download documents attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.
- Patch and upgrade any platforms and software timely and make it into a standard security policy. Prioritize patching known exploited vulnerabilities and zero-days.