{"id":4304,"date":"2025-05-30T10:03:36","date_gmt":"2025-05-30T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/30\/new-rust-based-infostealer-via-fake-captcha-delivers-eddiestealer\/"},"modified":"2025-05-30T10:03:36","modified_gmt":"2025-05-30T10:03:36","slug":"new-rust-based-infostealer-via-fake-captcha-delivers-eddiestealer","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/30\/new-rust-based-infostealer-via-fake-captcha-delivers-eddiestealer\/","title":{"rendered":"New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER"},"content":{"rendered":"<p>    New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have uncovered a sophisticated malware campaign leveraging deceptive CAPTCHA verification pages to distribute a newly discovered Rust-based infostealer dubbed EDDIESTEALER.<\/p>\n<p>This campaign represents a significant evolution in <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> tactics, where threat actors exploit users\u2019 familiarity with routine security verification processes to trick them into executing malicious code.<\/p>\n<p>The malware employs an intricate multi-stage delivery mechanism that begins with compromised websites displaying convincing fake \u201cI\u2019m not a robot\u201d verification screens, ultimately leading to the deployment of a powerful data-stealing tool capable of harvesting credentials, browser information, and <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallet<\/a> details.<\/p>\n<p>The attack vector demonstrates remarkable sophistication in its execution methodology. Initial access occurs through compromised websites that deploy obfuscated React-based JavaScript payloads, presenting users with what appears to be a legitimate Google reCAPTCHA verification interface.<\/p>\n<p>These fake verification screens instruct users to perform seemingly innocuous actions: pressing Windows Key + R to open the Run dialog, followed by Ctrl + V to paste clipboard contents, and finally Enter to execute the command.<\/p>\n<p>Unbeknownst to the victim, the malicious JavaScript has already copied a PowerShell command to their clipboard using the document.execCommand(\u201ccopy\u201d) method.<\/p>\n<p>Elastic Security Labs analysts <a href=\"https:\/\/www.elastic.co\/security-labs\/eddiestealer\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this emerging threat through comprehensive telemetry analysis, discovering that the campaign leverages a sophisticated command structure that silently downloads secondary payloads from attacker-controlled infrastructure.<\/p>\n<p>The PowerShell command automatically retrieves a JavaScript file named \u201cgverify.js\u201d from domains such as hxxps:\/\/1111.fit\/version\/, which subsequently downloads the main EDDIESTEALER executable with a pseudorandomly generated 12-character filename.<\/p>\n<p>This multi-layered approach effectively obscures the true nature of the attack while maintaining the appearance of legitimate system verification processes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgZmJc_KqkBP-4fCU_-F2kyKxoAinkwFZA95kE-2rYWo1ravDjj5AwmOoaAJYaGVaNcLzw88gYepGna1UrcEUOQ0RqJE1qQly56x1-ektG5wbXNqBhCBCEMFl1fp_awahN0G2-F7sGP9oNMKOphkQgbaTtooiWtFtV63h7aC8BIMwVKSvzdU-5c4NeDiPg\/s16000\/Fake%2520CAPTCHA%2520GUI%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake CAPTCHA GUI (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>The malware\u2019s impact extends far beyond simple credential theft, targeting a comprehensive range of sensitive data including cryptocurrency wallets, browser stored credentials, password manager databases, FTP client configurations, and messaging applications.<\/p>\n<p>EDDIESTEALER demonstrates particular sophistication in its approach to modern browser security, implementing techniques similar to ChromeKatz to bypass Application-bound encryption protections introduced in recent Chrome versions.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgkV29N3iqSnJsSgz4oP23kvK5XzXP8Gls8C4Gf-EyFfYXk9Qr2Cloeuc7aIaBEQhUeWihnjqIxlxU3hOqLkr5F2LkTLssBu9cEsN08w1IcMz7RXGKuUHJ06QWzQrWOZ-cjn97LJFoc0xaxuAYm5FzRyL_n1WB7NwCXPiNrXScyi5whEb9CP53x7ASwI3Q\/s16000\/EDDIESTEALER%25E2%2580%2599s%2520execution%2520chain%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">EDDIESTEALER\u2019s execution chain (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>The malware\u2019s ability to adapt to evolving security measures highlights the persistent threat posed by well-resourced cybercriminal organizations.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Evasion and Persistence Mechanisms<\/strong><\/h2>\n<p>EDDIESTEALER employs multiple layers of obfuscation and evasion techniques that distinguish it from conventional infostealers.<\/p>\n<p>The malware utilizes extensive string encryption through XOR ciphers, with each decryption routine employing distinct key derivation functions that accept binary addresses and 4-byte constants to calculate XOR key locations.<\/p>\n<p>This approach significantly complicates static analysis efforts, as researchers must reverse-engineer multiple custom decryption algorithms to extract meaningful artifacts.<\/p>\n<p>The malware implements sophisticated API <a href=\"https:\/\/cybersecuritynews.com\/hannibal-stealer-with-stealth-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a> through a custom Windows API lookup mechanism. Rather than relying on standard import tables, EDDIESTEALER dynamically resolves function addresses by maintaining a local hashtable of previously resolved API calls.<\/p>\n<p>When a new function is required, the malware employs custom LoadLibrary and GetProcAddress implementations to retrieve addresses, subsequently caching them for future use.<\/p>\n<p>This technique effectively evades signature-based detection systems that rely on import table analysis.<\/p>\n<p>EDDIESTEALER incorporates multiple anti-analysis features, including memory-based sandbox detection that evaluates total physical memory to determine if the system meets minimum requirements of approximately 4.0 GB.<\/p>\n<p>Additionally, newer variants suggest server-side profiling capabilities, where the command and control infrastructure can assess client environments and withhold malicious payloads when sandbox or analysis systems are detected.<\/p>\n<p>The malware also implements self-deletion capabilities using NTFS Alternate Data Streams renaming techniques, similar to those observed in LATRODECTUS <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>, enabling the executable to remove itself from disk while bypassing file lock restrictions.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Celebrate 9 years of ANY.RUN!\u00a0<strong>Unlock the full power of<\/strong>\u00a0TI Lookup plan (100\/300\/600\/1,000+ search requests),\u00a0and\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=linkedin_csn&amp;utm_medium=post&amp;utm_campaign=spring_offer&amp;utm_content=plans&amp;utm_term=290525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">your request quota will double<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\">New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER Cybersecurity researchers have uncovered a sophisticated malware campaign leveraging deceptive CAPTCHA verification pages to distribute a newly discovered Rust-based infostealer dubbed EDDIESTEALER. This campaign represents a significant evolution in social engineering tactics, where threat actors exploit users\u2019 familiarity with routine security verification processes to trick them into [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4304","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4304"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4304"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4304\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}