Security News > 2022 > March > Mars Stealer malware pushed via Google Ads and phishing emails
Cybercriminals trying to foist the Mars Stealer malware onto users seemingly have a penchant for one particulat tactic: disguising it as legitimate, benign software to trick users into downloading it.
In a recent campaign described by Morphisec malware researcher Arnold Osipov, the threat actor distributed the malware via cloned websites offering well-known software such as Apache Open Office.
"The actor is paying for these Google Ads campaigns using stolen information," Osipov noted.
In another campaign, documented by the Ukrainian CERT, a threat actor is pushing the malware via emails impersonating the Ministry of Education and Science of Ukraine, offering "a new program for writing in the magazine" to Ukrainian citizens and organizations.
Mars Stealer is relatively new malware based on the Oski Stealer.
The threat actor compromised his own computer with the Mars Stealer while debugging, so they gleaned even more insight and information that lead them to the actor's GitLab account and the discovery that the threat actor is a Russian speaker.
News URL
https://www.helpnetsecurity.com/2022/03/30/mars-stealer/
Related news
- SpyLoan Android malware on Google play installed 8 million times (source)
- 8 Million Android Users Hit by SpyLoan Malware in Loan Apps on Google Play (source)
- Ongoing Phishing and Malware Campaigns in December 2024 (source)
- European companies hit with effective DocuSign-themed phishing emails (source)
- Ongoing phishing attack abuses Google Calendar to bypass spam filters (source)
- Scams Based on Fake Google Emails (source)