Zhong Stealer Analysis: New Malware Targeting Fintech and Cryptocurrency

Feb. 19, 2025, 8:56 a.m.

Description

A new malware called Zhong Stealer has been identified targeting the cryptocurrency and fintech sectors through a phishing campaign. The attackers exploited chat support platforms, posing as customers to trick agents into downloading the malware. Zhong Stealer's execution flow involves multiple stages, including initial contact, downloader execution, persistence establishment, reconnaissance, credential theft, and data exfiltration. The malware uses various tactics such as disabling event logging, modifying registry keys, harvesting credentials, scheduling tasks, and communicating via non-standard ports. It exfiltrates stolen data to a command-and-control server in Hong Kong. Organizations are advised to train support teams, restrict file execution, monitor network traffic, and use real-time analysis tools to protect against this threat.

Date

  • Created: Feb. 18, 2025, 10:51 p.m.
  • Published: Feb. 18, 2025, 10:51 p.m.
  • Modified: Feb. 19, 2025, 8:56 a.m.

Indicators

  • e46779869c6797b294cb097f47027a5c52466fd11112b6ccd52c569578d4b8cd
  • 4eaebd93e23be3427d4c1349d64bef4b5fc455c93aebb9b5b752981e9266488e
  • 1abffe97aafe9916b366da57458a78338598cab9742c2d9e03e4ad0ba11f29bf
  • 02244934046333f45bc22abe6185e6ddda033342836062afb681a583aa7d827f
  • 156.245.23.188

Attack Patterns

  • Zhong Stealer

Additional Informations

  • Technology
  • Finance
  • Hong Kong