Jump to content
  • Beware: New Kraken botnet easily fools Windows Defender and steals Crypto wallet data

    Karlston

    • 574 views
    • 2 minutes
     Share


    • 574 views
    • 2 minutes

    Microsoft recently made an update to Window Defender Exclusions permission whereby it is no longer possible to view the excluded folders and files without administrator rights. This is a significant change as threat actors would often use this information to deliver malicious payloads inside such excluded directories in order to bypass Defender scans.

     

    However, this may not be able to stop a new botnet called Kraken which was recently discovered by ZeroFox. That's because Kraken simply adds itself as an exclusion instead of trying to look for excluded places to deliver the payload. This is a relatively simple and effective way to bypass Windows Defender scan.

     

    ZeroFox has explained how this works:

     

    During Kraken’s installation phase, it attempts to move itself into %AppData%\Microsoft.

    [...]

     

    To stay hidden, Kraken runs the following two commands:

     

    1. powershell -Command Add-MpPreference -ExclusionPath %APPDATA%\Microsoft

    2. attrib +S +H %APPDATA%\Microsoft\

     

    ZeroFox noted that Kraken is mainly a stealer malware, similar to the recently discovered Microsoft Windows 11 lookalike website. The security firm adds that Kraken's capabilities now include the ability to steal information related to users' cryptocurrency wallets, reminiscent of the recent fake KMSPico Windows activator malware.

     

    ZeroFox writes:

     

    The most recent feature addition is the ability to steal various cryptocurrency wallets from the following locations:

     

    • %AppData%\Zcash

    • %AppData%\Armory

    • %AppData%\bytecoin

    • %AppData%\Electrum\wallets

    • %AppData%\Ethereum\keystore

    • %AppData%\Exodus\exodus.wallet

    • %AppData%\Guarda\Local Storage\leveldb

    • %AppData%\atomic\Local Storage\leveldb

    • %AppData%\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb

     

    You can find more details about how Kraken works in the official blog post.

     

     

    Beware: New Kraken botnet easily fools Windows Defender and steals Crypto wallet data

    • Like 3

    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...