Masslogger malware employs 'fileless' attack to steal Discord and other passwords

Security Padlock
(Image credit: Pixabay)

Security researchers have discovered a malware campaign targeting Windows systems in an attempt to swipe login credentials from several popular applications, including Discord, Outlook, all major web browsers, NordVPN, and others. It does this through a multi-stage 'fileless' attack scheme.

Cisco Talos researcher Vanja Svajcer detailed the malware in a blog post, saying it is a variant of an existing trojan called Masslogger.

"Although operations of the Masslogger trojan have been previously documented, we found the new campaign notable for using the compiled HTML file format to start the infection chain," Svajcer explains.

Therein also lies a bit of good news—while the malware initiates attacks from within system memory (making it fileless), delivery of the payload relies on the tried and true vector of phishing emails, a longtime (and easily avoidable) staple of bad actors.

The infection is hidden inside a compressed RAR archive "with a slightly unusual filename extension," delivered to targets as an email attachment. When opened, it sets in motion a series of steps to inject malware into volatile memory (system RAM).

Svajcer says both home and business users are at risk, noting that this kind of malware can more easily slip under the radar right now because of the heightened awareness and focus on more predominant ransomware attacks.

"It is important to keep in mind that crimeware actors are still active and can inflict significant damage to organizations by stealing users' credentials. The credentials themselves have value on the dark web and actors sell them for money or use them in other attacks.," Svajcer writes.

Perfect peripherals

(Image credit: Colorwave)

Best gaming mouse: the top rodents for gaming
Best gaming keyboard: your PC's best friend...
Best gaming headset: don't ignore in-game audio

Interestingly, there is also a keylogger component to this version of Masslogger, but it has been disabled. Keyloggers and user credential theft typically go hand-in-hand.

The most recent Masslogger campaign began a month ago. Cisco Talos believes it is mostly focused on organizations in Turkey, Latvia, and Italy, at least for now. In the past, the security outfit has observed similar campaigns using previous versions of Masslogger in various other parts of the world.

Since this one relies on phishing emails to get started, it is easy to avoid—just keep using smart computing habits, like not downloading unexpected file attachments. Now would be a good time to remind any less savvy friends and family members to do the same.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Super Mario World
Super Nintendo consoles appear to be running ever-so-slightly faster as they age and speedrunning detectives are hot on the case
A photo of an Intel Core Ultra 9 285K processor surrounded by DDR5 memory sticks from Corsair, Kingston, and Lexar
Fresh leak suggests Intel's on-again-off-again Arrow Lake CPU refresh is back on the menu (boys)
A Colorful RTX 5080 and its box
Three lucky folks in India can win the dubious honour of buying an RTX 5080 GPU at Nvidia MSRP
The Facebook 'Like' emoji logo is seen in this photo illustration on 22 August, 2023 in Warsaw, Poland. (Photo by Jaap Arriens/NurPhoto via Getty Images)
Get ready to argue with your weird Uncle on Facebook again. Meta is rolling out its new fact checking solution to it's 190 million users in the United States
Gabe Newell in a Valve promotional video, on a yacht.
Go ahead and complain the discounts aren't as steep as they used to be, but Steam just had its biggest year ever for seasonal sales
Valve Steam Deck OLED handheld PC
'The future of hardware at Valve is bright': Valve celebrates the success of Steam Deck and Steam OS