#1 Trending Cyber Security News & Magazine
Wednesday, May 31, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Bl00dy ransomware

    Bl00dy Ransomware Claims First Indian Victim Via PaperCut Vulnerability

    MoChhatua Data Breach

    MoChhatua Data Breach: Hackers Claim Indian Local Governance App

    Drupal Vulnerabilities

    Multiple Drupal Vulnerabilities Discovered in File Chooser Field Module

    AV and EDR Killers

    ‘SentinelOne, ESET, Kaspersky’: Peddlers Claim to Sells AV and EDR Killers That Evade All Detection

    PixBankBot

    PixBankBot Targets Brazil’s Instant Payment Platform Pix

    Law firms and cybersecurity

    ALPHV Ransomware Group Hits BC Attorney: What’s With Law Firms and Cybersecurity?

    RaidForums Data Leak

    RaidForums Data Leak Exposes Over 470,000 Dark Web Users

    NoName hackers attack Lithuania

    Pro-Russia Hacker Group ‘NoName’ Claims Cyber Attack on Lithuania, Raise Security Concerns

    LockBit Leaks 700GB Data Post the MCNA Data Breach, Firm Informs Impacted Users

    LockBit Leaks 700GB Data Post the MCNA Data Breach, Firm Informs Impacted Users

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Martin Sloan, Five Years Of GDPR

    Five Years of GDPR: There is a Long Way to Run on Cross-Border Data Transfers

    Nokoyawa Ransomware Group

    All You Need to Know About The Nokoyawa Ransomware Group

    StopRansomware Guide

    Updated StopRansomware Guide Warns of Ransomware’s Shape Shifting Tactics

    Microsoft Entra

    Microsoft Build 2023: Microsoft Entra Introduced With New Identity and Access Features

    Data Protection Commission

    Irish Data Protection Commission imposes $1.3bn Fine on Meta

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    disclosing cybersecurity incidents

    Why Victims Fail to Disclose Cybersecurity Incidents, And Why They Should

    Stakeholder Communication During Crisis

    Stakeholder Communication During Crisis: How to Get It Right

    Government Regulation of AI businesses

    Government Regulation of AI businesses: UK Competition Watchdog Launches Review

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Cybertech Africa

    Cybertech Africa: The Pan-African Event for Innovation and Networking

    IBM Acquired Polar Security

    IBM Acquires Polar Security Reportedly For $60 Million

    World CyberCon Middle East 2023

    World CyberCon Middle East 2023: The Premier Cybersecurity Conference in the Region

    ODIN by Cyble

    Cyble Launches ODIN: A Revolutionary Tool for Unparalleled Internet Exploration

    cybersecurity investments

    Cybersecurity Investments Up in April, Market Watchers Predict Growth of Over $700 billion

    OilRig APT

    Experts Warn of Increased IT Supply Chain Attacks by OilRig APT in Middle East

    World Password Day 2023

    World Password Day 2023: Protect Your Password, Create an Unbreakable One

    national cybersecurity strategy

    US National Cybersecurity Strategy: Businesses, Let’s Start with Disclosure!

    Stack Identity

    Silicon Valley Startup, Stack Identity Receives $4 Million to Detect Shadow Access in Cloud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Bl00dy ransomware

    Bl00dy Ransomware Claims First Indian Victim Via PaperCut Vulnerability

    MoChhatua Data Breach

    MoChhatua Data Breach: Hackers Claim Indian Local Governance App

    Drupal Vulnerabilities

    Multiple Drupal Vulnerabilities Discovered in File Chooser Field Module

    AV and EDR Killers

    ‘SentinelOne, ESET, Kaspersky’: Peddlers Claim to Sells AV and EDR Killers That Evade All Detection

    PixBankBot

    PixBankBot Targets Brazil’s Instant Payment Platform Pix

    Law firms and cybersecurity

    ALPHV Ransomware Group Hits BC Attorney: What’s With Law Firms and Cybersecurity?

    RaidForums Data Leak

    RaidForums Data Leak Exposes Over 470,000 Dark Web Users

    NoName hackers attack Lithuania

    Pro-Russia Hacker Group ‘NoName’ Claims Cyber Attack on Lithuania, Raise Security Concerns

    LockBit Leaks 700GB Data Post the MCNA Data Breach, Firm Informs Impacted Users

    LockBit Leaks 700GB Data Post the MCNA Data Breach, Firm Informs Impacted Users

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Martin Sloan, Five Years Of GDPR

    Five Years of GDPR: There is a Long Way to Run on Cross-Border Data Transfers

    Nokoyawa Ransomware Group

    All You Need to Know About The Nokoyawa Ransomware Group

    StopRansomware Guide

    Updated StopRansomware Guide Warns of Ransomware’s Shape Shifting Tactics

    Microsoft Entra

    Microsoft Build 2023: Microsoft Entra Introduced With New Identity and Access Features

    Data Protection Commission

    Irish Data Protection Commission imposes $1.3bn Fine on Meta

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    US Police Auction Seized Cell Phones Without Wiping Data, Sparks Privacy Concerns

    disclosing cybersecurity incidents

    Why Victims Fail to Disclose Cybersecurity Incidents, And Why They Should

    Stakeholder Communication During Crisis

    Stakeholder Communication During Crisis: How to Get It Right

    Government Regulation of AI businesses

    Government Regulation of AI businesses: UK Competition Watchdog Launches Review

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Cybertech Africa

    Cybertech Africa: The Pan-African Event for Innovation and Networking

    IBM Acquired Polar Security

    IBM Acquires Polar Security Reportedly For $60 Million

    World CyberCon Middle East 2023

    World CyberCon Middle East 2023: The Premier Cybersecurity Conference in the Region

    ODIN by Cyble

    Cyble Launches ODIN: A Revolutionary Tool for Unparalleled Internet Exploration

    cybersecurity investments

    Cybersecurity Investments Up in April, Market Watchers Predict Growth of Over $700 billion

    OilRig APT

    Experts Warn of Increased IT Supply Chain Attacks by OilRig APT in Middle East

    World Password Day 2023

    World Password Day 2023: Protect Your Password, Create an Unbreakable One

    national cybersecurity strategy

    US National Cybersecurity Strategy: Businesses, Let’s Start with Disclosure!

    Stack Identity

    Silicon Valley Startup, Stack Identity Receives $4 Million to Detect Shadow Access in Cloud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Invicta Stealer Developers Exploit Facebook to Advertise Malware

Invicta stealer steals system and hardware data to know about the location of the target, their time zone, and the language on the system.

Vishwa Pandagle by Vishwa Pandagle
May 26, 2023 - Updated on May 31, 2023
in Firewall Daily, Malware News
0
Invicta Stealer
590
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

Researchers spotted a new infostealer, dubbed ‘Invicta Stealer’, being promoted by its developer on Facebook, leveraging the social media platform to connect to buyers and advertise the stealer on sale.

Interestingly, the threat actor had also created a YouTube channel to endorse the Invicta stealer. Several instances of using the Invicta stealer have been found due to its builder availability on GitHub.

You might also like

NoName Targets Lithuania Aviation Sector, Claims Avion Express, Heston Airlines Cyber Attack

Cyber Espionage Group Strontium Stealer Launches Remote Access Trojan LithiumRAT

Toyota Motor Customer Data Leak: Damage Deeper Than Expected, Says Company

Endorsement of the Invicta stealer

Invicta stealer

Increased usage rate of the Invicta stealer (Photo: Cyble)

Besides Facebook, YouTube, and GitHub, its developer offered a free stealer builder to increase its popularity and attract buyers. Some YouTube users have posted positive reviews on the platform about the info stealer.

How the Invicta stealer is sent to a user

Users are sent a spam email with an HTML page attached to it. The HTML page is designed to look like a refund invoice from GoDaddy. When the fraudulent refund HTML page is opened, a Discord page is opened which downloads another file named Invoice.zip.

The zip file contains a shortcut file named INVOICE_MT103.Ink. It requires the user to open the .lnk file which triggers a PowerShell command.

Invicta stealer

Infection chain of Invicta stealer (Photo: Cyble)

Researchers from the Cyble Research & Intelligence Labs analyzed a 64-bit GUI binary of the Invicta stealer from the wild to find out more about it. Following are the details found –

  1. Its SHA256 hash is 067ef14c3736f699c9f6fe24d8ecba5c9d2fc52d8bfa0166ba3695f60a0baa45.
  2. It has encrypted strings to hide its information.
  3. It uses SYSCALLS for its operations.
  4. It employs multithreading to perform multiple tasks simultaneously.

Data stolen using Invicta stealer

Invicta stealer steals system and hardware data to know about the location of the target, their time zone, and the language on the system.

The hardware data it requires were found to be main memory size, number of CPU cores, screen resolution, hardware ID, IP address, and Geo IP data.

Invicta stealer steals the following sensitive system information:

  1. Computer name
  2. System username, time zone, and language
  3. Operating system version
  4. Names of running processes
  5. Hardware data

The stolen data from the Invicta stealer is combined in a text file named sys_info.txt and stored in the memory to be sent to the hackers behind the operation. After the collection of all the data from the system, it temporarily stores it in the system’s memory.

Invicta creates a compressed zip file with a random name with the hardware ID as shown below:

Invicta stealer

(Photo: Cyble)

The file is sent to the C&C server or Discord webhook which the hacker uses to create further attacks such as stealing money from their wallets, and banks, and creating more relevant phishing emails with the target’s data.

Targets of the Invicta stealer

  • Discord – It is after stealing all the required information from the target, Invicta looks for the presence of the Discord application on the system to steal data from it.
  • Wallets – It looks for wallets on the system. It can steal from over 25 wallets as noted in the Cyble blog. Some of them are Neon, Zcash, VERGE, WalletWasabi, Exodus, Bitcoin, Coinomi, Dogecoin, Electrum, Litecoin, and so on.
  • Browsers – After looking for wallet data, the information stealer looks for browser data for credit card information, browser history, keywords, login data, etc. Over 30 browsers were noted on the Cyble blog that can be accessed by this information stealer. Some of them are Chromium, Yandex, Vivaldi, Opera Neon, 360Browser, Microsoft Edge, BraveSoftware, Google Chrome, etc.
  • Steam – The gaming application Steam is accessed to steal active gaming sessions, usernames, games installed, etc.
  • KeyPass password manager – This password manager that could contain passwords for websites and applications is also hacked by the Invicta stealer to gain credentials.

Loss of data and privacy

Invicta stealer

(Photo: Cyble)

The information stealer is equipped to steal most data from most locations of a system which makes it important to be detected and avoided at first glance of a phishing email. Catchy subjects such as refunds are used by hackers to make users think it is about an incoming credit.

A post made on May 13 by the seller of Invicta stealer wrote, “If we created a cheap subscription (up to $50-80 per month, compared to other stealers charging $150) which featured a web panel, would you use our product?”

“If you massively spread malware, send us a message as we have a proposition that will help you make way more money from your logs. Please don’t bother messaging us if you don’t know what you are doing, have low traffic, or don’t target cryptocurrencies,” the post further read.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: CRIL researcherscrypto wallet stealerCyble- bloginfostealer InvictaInvicta stealerThe Cyber ExpressThe Cyber Express News
Previous Post

Cyber Attack on the City of Augusta: BlackByte Ransomware Group Claims Hit

Next Post

Cybertech Africa: The Pan-African Event for Innovation and Networking

Vishwa Pandagle

Vishwa Pandagle

Vishwa Pandagle is a Technical Writer at The Cyber Express. She writes cybersecurity news related to data breaches, ransomware, phishing, and best practices among others. She also writes about cybersecurity developments and likes interacting with experts in this field. When not working, she likes self-reflecting, meditating, volunteering, and going for long walks.

Related Posts

Heston Airlines Cyber Attack
DDoS Attacks News

NoName Targets Lithuania Aviation Sector, Claims Avion Express, Heston Airlines Cyber Attack

by Vishwa Pandagle
May 31, 2023
LithiumRAT
Firewall Daily

Cyber Espionage Group Strontium Stealer Launches Remote Access Trojan LithiumRAT

by Vishwa Pandagle
May 31, 2023
Toyota Motor Customer Data Leak
Data Breach News

Toyota Motor Customer Data Leak: Damage Deeper Than Expected, Says Company

by Chandu Gopalakrishnan
May 31, 2023
Bl00dy ransomware
Firewall Daily

Bl00dy Ransomware Claims First Indian Victim Via PaperCut Vulnerability

by Chandu Gopalakrishnan
May 31, 2023
MoChhatua Data Breach
Firewall Daily

MoChhatua Data Breach: Hackers Claim Indian Local Governance App

by Ashish Khaitan
May 31, 2023
Next Post
Cybertech Africa

Cybertech Africa: The Pan-African Event for Innovation and Networking

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now

Download Now

CRIL


Follow Us On Google News

Never miss an update. Subscribe!

* indicates required

mailchimp

Latest Cyber News

Bl00dy ransomware
Firewall Daily

Bl00dy Ransomware Claims First Indian Victim Via PaperCut Vulnerability

May 31, 2023
MoChhatua Data Breach
Firewall Daily

MoChhatua Data Breach: Hackers Claim Indian Local Governance App

May 31, 2023
Drupal Vulnerabilities
Firewall Daily

Multiple Drupal Vulnerabilities Discovered in File Chooser Field Module

May 31, 2023
AV and EDR Killers
Firewall Daily

‘SentinelOne, ESET, Kaspersky’: Peddlers Claim to Sells AV and EDR Killers That Evade All Detection

May 30, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cyber Security News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance