World Health Organization Spoofing Campaign Drops Stealer
released on 2020-12-02 @ 03:38:55 PM
A collection of activity spoofing World Health Organization (WHO) to deliver generic stealers / commodity malware. Primary stealer to drop is Ficker, which is a malware-as-a-service family with many expected features:
Functional:
- Recursive stealing passwords, credit cards, forms from Chromium-Based, Mozilla (40+ browser).
- Stealing sessions cryptocurrency wallets
- Stealing from Windows Credentials Manager
- Stealing sessions from Pidgin, Steam, Discord, ThunderBird, etc (optional)
- Stealing FTP clients (FileZilla, WinScp)
- Stealing system information
- Taking screenshot
- Universal grabber
- Using memory for executing
- Server-side decrypting passwords, generating zip archive.