Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The downloaded .RAR file contains a Windows Shortcut file (.lnk) which downloads the Powershell script. This method exploits WinRAR Code Execution Vulnerability (CVE-2023-38831). | In early December, during an Advanced Continual Threat Hunt (ACTH) campaign investigation, Trustwave SpiderLabs discovered a new malware named Ov3r_Stealer. At a high level, this malware is designed to steal credentials and crypto wallets and send those to a Telegram channel that the threat actor monitors.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors are leveraging bogus Facebook job advertisements as a lure to trick prospective targets into installing a new Windows-based stealer malware codenamed Ov3r_Stealer.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
a Scheduled Task created called “Licensing2” which runs every 90 minutes
/F /CREATE /TN “Licensing2” /tr “C:\Users\Public\Libraries\Books\WerFaultSecure.exe” /sc minute /MO 90
the malicious .cpl file was executed using the following command from rundll32: shell32.dll, Control_RunDLL <.cpl path>. Instead of modifying system settings, the .cpl file is used to run a remote PowerShell script.
The execution of the CPL file leads to the retrieval of a PowerShell loader ("DATA1.txt") from a GitHub repository to ultimately launch Ov3r_Stealer.
The downloaded .RAR file contains a Windows Shortcut file (.lnk) which downloads the Powershell script. This method exploits WinRAR Code Execution Vulnerability (CVE-2023-38831).
we found some sample data that would indicate another method of executing the loaders, which involved HTML Smuggling. In this example, a weaponized HTML file, CustomCursor.html is used to load the CustomCursor.zip file.
Ov3r_Stealer is capable of siphoning IP address-based location, hardware info, passwords, cookies, credit card information, auto-fills, browser extensions, crypto wallets, Microsoft Office documents, and a list of antivirus products installed on the compromised host.
Ov3r_Stealer is capable of siphoning IP address-based location, hardware info, passwords, cookies, credit card information, auto-fills, browser extensions, crypto wallets, Microsoft Office documents, and a list of antivirus products installed on the compromised host.
Ov3r_Stealer is capable of siphoning IP address-based location, hardware info, passwords, cookies, credit card information, auto-fills, browser extensions, crypto wallets, Microsoft Office documents, and a list of antivirus products installed on the compromised host.
This malware is designed to steal credentials and crypto wallets and send those to a Telegram channel that the threat actor monitors.
129 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-based stealer malware designed to steal credentials, crypto wallets, IP-based location, hardware information, passwords, cookies, credit card data, autofill data, browser extensions, Microsoft Office documents, and antivirus product lists, then exfiltrate the data to a Telegram channel monitored by the threat actor.
Credential- and crypto-wallet-stealing malware for Windows that uses multiple delivery and loader methods, establishes persistence via Scheduled Task, collects browser data, cookies, credit cards, autofill data, extensions, wallet files, documents, Discord data, FTP credentials, and system information, then exfiltrates the data to Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.