Security News > 2022 > March > Mars Stealer malware pushed via Google Ads and phishing emails

Mars Stealer malware pushed via Google Ads and phishing emails
2022-03-30 13:12

Cybercriminals trying to foist the Mars Stealer malware onto users seemingly have a penchant for one particulat tactic: disguising it as legitimate, benign software to trick users into downloading it.

In a recent campaign described by Morphisec malware researcher Arnold Osipov, the threat actor distributed the malware via cloned websites offering well-known software such as Apache Open Office.

"The actor is paying for these Google Ads campaigns using stolen information," Osipov noted.

In another campaign, documented by the Ukrainian CERT, a threat actor is pushing the malware via emails impersonating the Ministry of Education and Science of Ukraine, offering "a new program for writing in the magazine" to Ukrainian citizens and organizations.

Mars Stealer is relatively new malware based on the Oski Stealer.

The threat actor compromised his own computer with the Mars Stealer while debugging, so they gleaned even more insight and information that lead them to the actor's GitLab account and the discovery that the threat actor is a Russian speaker.


News URL

https://www.helpnetsecurity.com/2022/03/30/mars-stealer/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 995 4921 2871 1623 10410