Friday, November 27, 10:34
Home security Hackers use Telegram as C2 Server and share Masad Stealer ...

Hackers use Telegram as C2 Server and share Masad Stealer malware

MasadAccording to researchers, a new one is being released trojan, called Masad Stealer and is used to monitor victim systems and data theft.

Masad Stealer uses Telegram as a command and control channel, in order to maintain the anonymity and hide malicious activity.

Telegram is often used by dangerous people hackers to carry out attacks.

Masad Stealer has been advertised in underground hacking forums as spyware that can he steals data of browser, usernames, passwords access and information credit cards.

The malicious campaign used by Masad Stealer targets thousands victims around the world right now. Researchers believe it will cause many problems.

"This malware is advertised in various hacks Forums as Masad Stealer. It starts with a free version and continues with versions that require up to $ 85. Every version of malware offers different features. "

Masad Stealer: Infection

The administrators of Masad Stealer are using Autoit script to write malware and later convert it to an executable file Windows. If users execute it, malicious software will be installed in% APPDATA% \ folder_name} {file_name}.

Once installed, the following sensitive information begins to be collected:

  • Cryptocurrency Wallets
  • Information about computers and systems
  • Credit card details
  • Browser data
  • Browser cookies
  • passwords
  • Software
  • Desktop screenshots
  • Desktop files
  • Steam files
  • Discord and Telegram data
  • FileZilla files

The administrators of Masad Stealer use a variety of methods to distribute malware.

One researcher mentioned several legitimate software such as CCleaner.exe, Iobit v 1.7.exe, Whoami.exe, Galaxy Software Update.exe, which mimic malware to deceive them. users and make them install it.


Please enter your comment!
Please enter your name here

Absent Mia
Absent Mia
Being your self, in a world that constantly tries to change you, is your greatest achievement


North Korean hackers tried to intervene in vaccine trials

According to the authorities, the South Korean intelligence service prevented attempts by hackers from North Korea to stop the development tests ...

Britain: E-commerce platform leaked data

The Criminal Investigation Department (CID) in collaboration with the cybercrime prosecution of England, are conducting investigations to identify a malicious agent, ...

Russia: Will it ban social media sites that censor Russian news agencies?

Russia plans to introduce a new bill that would ban foreign social media sites in the country. This comes after ...

Egregor ransomware: It becomes more and more dangerous following in the footsteps of Maze

Security experts warn that a new ransomware group is rapidly escalating its threatening activity, carrying out double blackmail attacks on numerous victims ...

The value of Bitcoin and other digital currencies fell

The value of Bitcoin and other digital currencies fell on November 25, which triggers scenarios regarding the duration of the explosion ...

Which are the countries with the most economical internet?

Although the Internet is available in almost every country in the world, the cost of subscription, speeds and salaries of citizens ...

How to choose which extensions will appear in the Firefox toolbar

If you are using extensions with Mozilla Firefox and want to add or remove some extension icons from the toolbar, you can ...

WhatsApp OTP Scam: steps to avoid hackers

WhatsApp is gaining more and more reputation as one of the most used mobile messaging applications worldwide, with more users ...

Sophos notifies some customers that their personal information has been exposed

The British cybersecurity and hardware company Sophos sent an email to some of its customers to inform them that their personal ...

A $ 6 million fine was imposed on Facebook for data sharing

Facebook has been fined 6,7 billion won (about $ 6 million) for sharing user data from Korea without ...