Target Industry

Indiscriminate.

Overview

Security researchers at CYFIRMA have produced an analysis of a .NET-based information-stealing malware. PupkinStealer is designed to harvest sensitive user data, including browser credentials, desktop files, messaging sessions (Telegram and Discord), and desktop screenshots. 

Impact

PupkinStealer malware is likely to pose as a high impact to both individuals and organisations. It compromises user privacy and can lead to identity theft and financial fraud. For organisations, the theft of credentials and sensitive data increases security risks, potentially resulting in data breaches, reputation damage, and substantial financial losses. 

Exploitation

The PupkinStealer malware is typically deployed through phishing emails, malicious attachments, or compromised websites. The malware uses decryption keys from Chromium-based browsers to extract saved login credentials. It hijacks sessions and copies the Telegram’s data folder, which extracts Discord tokens for unauthorised access. The stolen data is saved into a ZIP archive and sent to a remote server via Telegram Bot API. 

Indicators of Compromise

The table below outlines some of the indicators of compromise (IoC) taken from GBHackers: 

 

IoC Type IoC Value 
File Path %APPDATA%\Temp$Username]\Grabbers\Browser\passwords.txt 
MD5 fc99a7ef8d7a2028ce73bf42d3a95bce 
SHA-256 9309003c245f94ba4ee52098dadbaa0d0a4d83b423d76c1bfc082a1c29e0b95f 
Telegram Bot Token 8013735771:AAEUrTgQsAmiAsXeDN6mehDfo3vEg-kCM 
URL https[:]//api[.]telegram[.]org/bot[BotToken]/sendDocument?chat_id=7613862165&caption 

Containment, Mitigations & Remediations

It is highly recommended to Implement robust cyber security measures, such as endpoint security solutions, network monitoring, and user education to mitigate the risks associated with PupkinStealer. 

Threat Landscape

The possible risk to organisations of PupkinStealer malware is substantial. This is due to its design for rapid deployment and data harvesting without complex obfuscation or persistence mechanisms. It reflects the growing sophistication of malware and the use of platforms like Telegram for command-and-control operations. 

Threat Group

The threat actor group behind PupkinStealer is attributed to a developer known as Ardent. This attribution is based on embedded code strings and other identifiers found within the malware. Ardent is believed to be a Russian-speaking developer, which aligns with the use of Telegram for exfiltration and other operational details  

Further Information

Cyfirma report 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content