Blast from the Past
Essential information
- Published
- 05/02/2025 02:45
- Modified
- 05/02/2025 11:17
- Tags
- 2025-02-05 credential-theft data exfiltration maas nova organizations persistence phishing russian snakelogger stealer
- Related entities
- 1 observables, 16 techniques (mitre), 2 malware, 1 others
Description
A large-scale campaign targeting Russian organizations across various industries has been detected. The attackers are using NOVA stealer, a commercial fork of SnakeLogger, distributed via phishing emails disguised as contract archives. NOVA, marketed as Malware-as-a-Service, is capable of stealing credentials, capturing keystrokes, taking screenshots, and extracting clipboard data. The malware gains persistence through Windows Task Scheduler and injects itself into a spawned child process. Data exfiltration is performed via SMTP. The campaign highlights the growing threat of stealers and the potential for harvested data to be used in future targeted attacks.