3 October 2023

New BunnyLoader malware helps to steal credentials, crypto coins


New BunnyLoader malware helps to steal credentials, crypto coins

A new malware-as-a-service (MaaS) threat known as “BunnyLoader” is being advertised for sale on various underground forums, according to a new report from cloud security firm Zscaler ThreatLabz.

Written in C/C++, BunnyLoader is filless, operating mostly in memory. The malware, which is under active development, comes with a slew of functionalities, such as the ability to download and execute a second-stage payload, steal browser credentials and system information, log keystrokes, and thwart analysis attempts. It can also monitor the victim’s clipboard and replace cryptocurrency wallet addresses with actor-controlled crypto wallets, and supports remote command execution.

The BunnyLoader command-and-control panel showcases a list of various tasks, including downloading and executing additional malware, keylogging, stealing credentials, manipulating a victim’s clipboard to steal cryptocurrency, and running remote commands on the infected machine.

Since its initial release on September 4, 2023, BunnyLoader went through several feature updates, introducing new functionalities. Currently, the tool is being sold for $250, while the ‘private stub’ version, which implements more advanced features is being offered for $350.

Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024