{"id":4974,"date":"2024-08-21T15:06:54","date_gmt":"2024-08-21T20:06:54","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake"},"modified":"2024-08-21T15:06:54","modified_gmt":"2024-08-21T20:06:54","slug":"styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/21\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake\/","title":{"rendered":"&#8216;Styx Stealer&#8217; Blows Its Own Cover With Sloppy OpSec Mistake"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt07cd054d01a6a1c8\/66c63cf863008541bdc600c5\/hacker_BLKstudio_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security researchers were able to gather valuable information on the creator of a sophisticated new malware tool called Styx Stealer because of a basic operational security lapse on the part of the threat actor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The slipup allowed the researchers \u2014 from Check Point Research (CPR) \u2014 to identify the malware author as an individual operating out of Turkey and having connections with the operator of an Agent Tesla campaign, one of the oldest and most prolific information stealers still in use. The lapse also allowed researchers to gather other personal details, including the malware developer&#8217;s Telegram accounts, contacts, emails, and cryptocurrency transfers over a two-month period, totaling some $9,500 from purchasers of Styx Stealer and a separate encryption tool.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Fortuitous OpSec Failure\">A Fortuitous OpSec Failure<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;During the debugging of Styx Stealer, the developer made a fatal error and leaked data from his computer,&#8221; CPR researcher Alexey Bukhteyev wrote <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2024\/unmasking-styx-stealer-how-a-hackers-slip-led-to-an-intelligence-treasure-trove\/?web_view=true\" rel=\"noopener\">in a recent blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;[This] allowed CPR to obtain a large amount of intelligence, including the number of clients, profit information, nicknames, phone numbers, and email addresses, as well as similar data about the actor behind the Agent Tesla campaign.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Instances of threat actors inadvertently doxing themselves via operational security lapses, while somewhat rare, still keep happening. And when they do, security researchers have been quick to capitalize on those errors and harvest as much detail as they are able to on the threat actor&#8217;s tactics, techniques, and procedures.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Threat actors regularly abet their own discovery. Last year, Mandiant was able to attribute an attack on enterprise directory-as-a-service provider JumpCloud to North Korea&#8217;s Lazarus Group after a security oversight exposed the threat&#8217;s actual IP address in North Korea. Similar errors \u2014 in this case, not cleaning up properly after a ransomware attack \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.secureworks.com\/blog\/opsec-mistakes-reveal-cobalt-mirage-threat-actors\" rel=\"noopener\">allowed Secureworks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to expose the personas and companies behind Iranian threat group Cobalt Mirage. In 2021, researchers at IBM&#8217;s X-Force threat intelligence group <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/how-threat-analysts-learned-from-attackers-opsec-mistakes\" rel=\"noopener\">scooped up valuable information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on Iran&#8217;s &#8220;Charming Kitten&#8221; cyber-espionage group because of multiple operational security failures on the threat actor&#8217;s part.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Putting Together the Pieces\">Putting Together the Pieces<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CPR researchers got their first clues about Styx Stealer&#8217;s author when analyzing a malicious file containing Agent Tesla that they recovered from a spam campaign this past March. They found the malware using Telegram&#8217;s Bot API for data exfiltration and managed to extract the Telegram bot token from it. This allowed CPR researchers to monitor the threat actor&#8217;s Telegram bot.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That in turn led to the discovery of a malicious archive file with a document titled &#8220;Styx Stealer&#8221; and a screenshot showing someone working in Visual Studio on a project named &#8220;PhemedroneStealer,&#8221; debugging a process titled &#8220;Styx-Stealer.exe.&#8221; The program file in the project contained a hard-coded Telegram bot token and chat ID that were identical to what CPR researchers had extracted from the Agent Tesla sample.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Working from there, the researchers were able to piece together information that eventually led to their identifying Styx Stealer&#8217;s author as a Turkey-based individual using the handle Sty1x and a couple of different email addresses and phone numbers. Their analysis showed Sty1x worked with an individual using the handle @Mack_Sant based in Lagos, Nigeria. Exchanges between the two showed Sty1x using @Mack_Sant to test Styx Stealer&#8217;s ability to exfiltrate data initially using a Styx Stealer-specific Telegram bot and then the Agent Tesla bot.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data that the researchers were able to recover from the computers of both individuals \u2014 and visible in photos that @Mack_Sant sent to Sty1x of a phone and laptop \u2014 showed the former to be the operator of the Agent Tesla campaign that CPR investigated in March. &#8220;We also see a screenshot of Agent Tesla reports, which fully confirms our suspicion that @Mack_Sant (also known as @Fucosreal) is the owner of this bot and the originator of the Agent Tesla campaign,&#8221; Bukhteyev wrote.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Slick Infostealer\">A Slick Infostealer<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Styx Stealer itself is an information stealer that is based on an early version code associated with &#8220;Phemedrone Stealer,&#8221; a malware tool that researchers observed being used in attacks that targeted <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-zero-days-allow-defender-bypass-privilege-escalation\" rel=\"noopener\">CVE-2023-36025<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a Windows Defender SmartScreen vulnerability from earlier this year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malware steals data from browser extensions in Chromium-based browsers, from cryptocurrency wallets, and from files within &#8220;My Documents&#8221; and &#8220;Desktop&#8221; folders. It can also obtain location and system data and steal Discord, Telegram, and Steam sessions, CPR said. Like many malware tools, Styx Stealer packs multiple obfuscation and detection evasion features, including those that check for and terminate certain processes and determine if it might be running in a virtual machine. The malware is designed so it won&#8217;t execute in specific countries, including Russia, Ukraine, Kazakhstan, Moldova, Belarus, and Azerbaijan.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The case of Styx Stealer is a compelling example of how even sophisticated cybercriminal operations can slip up due to basic security oversights,&#8221; Bukhteyev said.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers were able to gather valuable information on the<\/p>\n","protected":false},"author":12,"featured_media":4975,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4974","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/styx-stealer-blows-its-own-cover-with-sloppy-opsec-mistake.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4974"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4974\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4975"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}