Skip to main content

CopperStealer Trojan

CopperStealer is an information stealing trojan with additional dropper capabilities. It is delivered through software cracking and keygen sites. Similarities in its target and delivery methods suggest it is related to the older SilentFade malvertising campaign.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CopperStealer is an information stealing trojan with additional dropper capabilities. It is delivered through software cracking and keygen sites. Similarities in its target and delivery methods suggest it is related to the older SilentFade malvertising campaign.


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

First observed in July 2019, CopperStealer (also known as Mingloa) is a credential harvesting trojan with similarities to the SilentFade malware family. It appears to still be in active development, with at least 60 known versions in the wild and several updates a month. As well as collecting user information and cookies from most popular browsers, CopperStealer will also attempt to download other payloads to affected systems.


Delivery

CopperStealer is distributed through third-party sites claiming to circumvent software licensing restrictions (commonly referred to as ‘crack’ or ‘keygen’ sites).


Activities

Once executed, CopperStealer will perform several anti-analysis checks before attempting to open a specific registry key, creating it if it is not already present. It then loads a hardcoded certificate into the system’s trusted root store.

CopperStealer will attempt to extract user credentials and cookies for a variety of social media, shopping, and service providers from the following internet browsers: Google Chrome, Microsoft Edge, Mozilla Firefox, Opera, and Yandex. This information is then used to make requests for additional information from the relevant APIs. All collected information is then encrypted and sent to a command and control (C2) server via POST request.

CopperStealer will also drop an apparently legitimate copy of the Xunlei download manager to the systems once it has extracted all information. This is then used to install secondary payloads, with configuration data passed from CopperStealer to the downloader.


Remediation advice

To prevent and detect an infection, NHS Digital advises that:

  • Secure configurations are applied to all devices.
  • Security updates are applied at the earliest opportunity.
  • Tamper protection settings in security products are enabled where available.
  • Obsolete platforms are segregated from the rest of the network.
  • IT usage policies are reinforced by regular training to ensure all users know not to open unsolicited links or attachments.
  • Multi-factor authentication (MFA) and lockout policies are used where practicable, especially for administrative accounts.
  • Administrative accounts are only used for necessary purposes.
  • Remote administration services use strongly encrypted protocols and only accept connections from authorised users or locations.
  • Systems are continuously monitored, and unusual activity is investigated, so that a compromise of the network can be detected as early as possible.

Please note that the NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages.


Indicators of compromise

Network indicators

Domains

  • 52959825ae41ce72[.]com
  • 574e0f440d5d411d[.]com
  • 687b318f1a4e0afc[.]com
  • 768deefde7eecd74[.]com
  • 844106c92ac5210a[.]com
  • 9a3a97f6f45f2c2b[.]com
  • a36e971e03d9cbf8[.]com
  • back19e64ea00d6ecfe1[.]io
  • c41676c07a61a961[.]com
  • c8224b778f8d7e73[.]com
  • eaa5cd71691e472c[.]com
  • ru94cb2b5ed89d7c[.]ru
  • su94cb2b5ed89d7c[.]su
Host indicators

SHA256 hashes

  • 1088966f9f137b15a34da54765d7773743a77da4ac2f70e82e6d603af28cf58e
  • 10bb601f27c0aae7fb9cc88a45434a8dcd759c03698c00b322f8b7f78ed64164
  • 1edec40732a728195ffea9946dd65ede6072c3c5061cfa3cc6e7cf6b7769052c
  • 2101fe7d90649a84586e01a615330c95db03c33327cae640cd0e2d7a36f3f2cc
  • 3225ce04d0b89652ac6b1f59180eefd41b5a6fdcbabd9066da710cdab462383e
  • 42e2411108492987315588c71e15f3e6ad266bd380a6f8c6607a577414a332bb
  • 449973a46282cfbce784d86b42a26a5a259b3f552627986aec57bac4902d3461
  • 5fa60303a0c4fd13ecd69e7c1a17788b72605473c2fb3f93eb758010326c76e5
  • 6ec80bae15601abfa57fc8ca0a3a83bd6af876a47123c3d8a0ac1761ca3b1289
  • 772062075a6ce77768bd462428eb6554ccaefec146f2f79cf22032614364d800
  • 77daf2ac4fd26e13adbd6b7db03c1fadd30cafc513d03a8412896bb6b4f0f39b
  • 81202529443a234489720c0030b05d3b5c28fe046a412953e95110699cc9b7cf
  • 8b4c5372b95dbc8705b82f2223b6086795004b5ad559091f607a43d0b5038595
  • b2996f082d4b43cf9ea3de083ba882269b5f63d6ac53bf31449831e75cb6e4a9
  • b3681d24634f9b10af333470d1f50404fce978bd78bbe22a283716327cfd48c1
  • daa6931054a125d49f43537a7c07a3bfad8854e18c0c25b49ad7808040f92bb8
  • ebcc7681c6634a22090b9eec8e1a82151173bb74d6668c3e7915a7558b2e9fbe
  • f9188822ce06ba4017508737fd6304babaee4832cfb94803b7ef83e0de9d5327
  • 729b2cb357db3f9fbca4eff18274c5ce59e4fd18e944c3d36cc7e04f8453a9f6
  • e03f2a3c636d458e8122361377ba641b1b7d6b5ff950948820359e5eebed4221

Last edited: 21 December 2021 10:49 am