• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new mranon stealer malware targeting german users via booking themed scam

New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

You are here: Home / General Cyber Security News / New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam
December 12, 2023

A phishing marketing campaign has been observed delivering an information stealer malware referred to as MrAnon Stealer to unsuspecting victims by means of seemingly benign scheduling-themed PDF lures.

“This malware is a Python-centered data stealer compressed with cx-Freeze to evade detection,” Fortinet FortiGuard Labs researcher Cara Lin said. “MrAnon Stealer steals its victims’ credentials, method information, browser periods, and cryptocurrency extensions.”

There is proof to counsel that Germany is the principal concentrate on of the attack as of November 2023, owing to the range of occasions the downloader URL hosting the payload has been queried.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Masquerading as a firm looking to reserve hotel rooms, the phishing email bears a PDF file that, upon opening, activates the an infection by prompting the receiver to download an current edition of Adobe Flash.

Cybersecurity

Carrying out so success in the execution of .NET executables and PowerShell scripts to eventually operate a pernicious Python script, which is capable of accumulating information from several apps and exfiltrating it to a public file-sharing web-site and the menace actor’s Telegram channel.

It can be also able of capturing data from fast messaging apps, VPN clientele, and documents matching a sought after listing of extensions.

MrAnon Stealer

MrAnon Stealer is made available by the authors for $500 for every thirty day period (or $750 for two months), along with a crypter ($250 per month) and a stealthy loader ($250 for every thirty day period).

“The marketing campaign at first disseminated Cstealer in July and August but transitioned to distributing MrAnon Stealer in October and November,” Lin mentioned. “This sample indicates a strategic approach involving the ongoing use of phishing e-mails to propagate a wide range of Python-based mostly stealers.”

The disclosure will come as the China-joined Mustang Panda is behind a spear-phishing email marketing campaign focusing on the Taiwanese authorities and diplomats with an aim to deploy SmugX, a new variant of the PlugX backdoor that was earlier uncovered by Check Point in July 2023.

Located this report appealing? Adhere to us on Twitter  and LinkedIn to examine much more unique material we publish.


Some sections of this short article are sourced from:
thehackernews.com

Previous Post: «apple releases security updates to patch critical ios and macos Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
Next Post: Non-Human Access is the Path of Least Resistance: A 2023 Recap non human access is the path of least resistance: a 2023»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.