Mandiant analyzed the workstations belonging to the end user and discovered that some systems had been infected with CRYPTBOT, an info-stealer malware, shortly before the stolen session token was generated.
CRYPTBOT
CryptBot is a Windows infostealer focused on harvesting sensitive user and system data from infected hosts.
Profile source: Mallory opens in a new tabCRYPTBOT
Family profile
CryptBot is a Windows infostealer focused on harvesting sensitive user and system data from infected hosts. It is commonly distributed through fake software-download ecosystems, especially sites masquerading as sources for cracks, key generators, activators, serials, and free versions of commercial software. Operators have also used trojanized installers, including altered activators and modified software packages, and have relied on search-engine manipulation to drive victims to malicious landing pages. CryptBot has also appeared in broader commodity-malware delivery campaigns and in some cases has been delivered through loader or sideloading chains rather than directly.
The malware steals browser-stored credentials, cookies, browsing data, credit card information, and cryptocurrency-wallet data, and has also been observed collecting system profiling information and, in some versions, screenshots and selected files. Targeted applications have included major Chromium-based browsers and Firefox-family browsers, along with numerous desktop cryptocurrency wallets and wallet-related browser extensions. Stolen data is typically staged, often compressed into an archive, and exfiltrated to command-and-control infrastructure. Some variants also download and execute secondary payloads, most notably ClipBanker, and observed follow-on payloads have included other commodity malware.
CryptBot operators frequently change packing, loaders, filenames, scripts, and infrastructure to reduce detection. Reported execution chains include multi-layer archives, self-extracting packages, AutoIt-based loaders, in-memory decryption, manual DLL loading, and process hollowing or related injection techniques. Anti-analysis and defense-evasion behaviors reported across variants include anti-VM or anti-sandbox checks, duplicate-infection checks, self-deletion in some versions, obfuscation, and limited disk artifacts through in-memory execution. Infrastructure patterns have repeatedly involved rapidly rotated command-and-control servers, often using short-lived domains.
CryptBot has been active since at least 2019 and has been associated with large-scale criminal distribution operations affecting hundreds of thousands of systems. Public reporting and civil litigation have linked major distribution activity to cracked-software ecosystems and operators based in Pakistan. The malware is broadly opportunistic, but campaigns have particularly targeted users seeking pirated software and, in some reporting, users of Google Chrome because of the stealer’s emphasis on browser data theft.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Post Exploitation
- Process Injection
- Session Hijacking
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK