Warning: Styx Stealer Malware Compromises Browser and Messaging App Data

Recently, cybersecurity experts from Check Point unearthed a new form of malware called “Styx Stealer,” designed to pilfer data from web browsers and instant messaging platforms.

These malicious tools, known as stealers, are commonly used by threat actors to covertly extract sensitive information from infected devices. This includes personal credentials, financial details, and passwords.

The stolen data is often leveraged for further attacks, identity theft, or sold illicitly, underscoring the significant role stealers play in the realm of cybercrime.

Technical Overview

Styx Stealer, a sophisticated malware variant, first appeared online in April 2024. It evolves from the Phemedrone Stealer, incorporating notable enhancements.

Targeting browsers built on Chromium and Gecko engines, Styx Stealer is capable of extracting saved passwords, cookies, auto-fill data, and details from cryptocurrency wallets. It also compromises Telegram and Discord sessions, collects system data, and captures screenshots.

Distinctive features of this malware include auto-start capabilities, real-time clipboard monitoring, and crypto-clipping functions. Styx Stealer has been engineered to evade detection by antivirus solutions and sandbox environments more effectively than its predecessor.

Developed by a Turkish cybercriminal known as “Sty1x,” Styx Stealer is available for purchase through Telegram or a dedicated site, with subscription options ranging from $75 per month to $350 for unlimited use.

Investigations revealed that Sty1x collaborated with a Nigerian criminal under the aliases Fucosreal and Mack_Sant, previously associated with the Agent Tesla malware campaign.

Their operations primarily targeted Chinese enterprises across sectors like metallurgy, transportation, and manufacturing.

A lapse in operational security exposed Sty1x’s development activities, personal information, and the complex web of connections within the cybercrime network, unraveling intricate international criminal networks.

Styx Stealer, an upgraded version of the older Phemedrone Stealer, features enhancements such as a crypto-clipper, improved evasion techniques, and a configurable graphical interface builder.

Sty1x inadvertently disclosed his operation by debugging the malware with a Telegram bot token from @Mack_Sant (also known as Fucosreal), who was linked to the Agent Tesla campaign. This breach unveiled their identities, email addresses, and affiliations with cybercriminal groups.

Styx Stealer and its associated tool, Styx Crypter, are marketed through Telegram (@styxencode), with transactions conducted using cryptocurrencies like Bitcoin, Litecoin, Tron USDT, and Monero.

Forensic analysis identified 54 customers and approximately $9,500 in revenue over two months across eight cryptocurrency wallets.

Styx Stealer’s design includes anti-VM and geo-blocking features to evade detection in CIS countries, focusing on extracting browser data, cryptocurrency wallet details, and system information. Despite these efforts, the distribution of Styx Stealer appears to have been largely ineffective, with no confirmed victims other than the malware’s own infrastructure and several security sandboxes.

More Articles & Posts