{"id":6946,"date":"2025-09-16T10:03:37","date_gmt":"2025-09-16T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/16\/new-maranhao-stealer-via-pirated-software-leveraging-cloud-hosted-platforms-to-steal-login-credentials\/"},"modified":"2025-09-16T10:03:37","modified_gmt":"2025-09-16T10:03:37","slug":"new-maranhao-stealer-via-pirated-software-leveraging-cloud-hosted-platforms-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/16\/new-maranhao-stealer-via-pirated-software-leveraging-cloud-hosted-platforms-to-steal-login-credentials\/","title":{"rendered":"New Maranh\u00e3o Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials"},"content":{"rendered":"<p>    New Maranh\u00e3o Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Since May 2025, a novel credential stealer dubbed <strong>Maranh\u00e3o Stealer<\/strong> has emerged as a significant threat to users of pirated gaming software. Distributed through deceptive websites hosting cracked launchers and cheats, the malware leverages cloud-hosted platforms to deliver trojanized installers that appear innocuous.<\/p>\n<p>Upon execution, the installer unpacks a Node.js\u2013compiled binary encapsulated in an Inno Setup executable, initiating a silent infection process that avoids user detection while harvesting sensitive data.<\/p>\n<p>In its initial <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>, threat actors attracted victims with enticing download links such as <code>DerelictSetup.zip<\/code>, promising modified game content.<\/p>\n<p>Behind the scenes, however, the Inno Setup wrapper drops several components, including <code>updater.exe<\/code>, <code>crypto.key<\/code>, and <code>infoprocess.exe<\/code>, into a hidden \u201cMicrosoft Updater\u201d directory under <code>%localappdata%Programs<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEicqzy724nXSoJQrOL4-B5SNykBGJUUeAWldWL_AgjFpfXOO2NPLJyPPR23swC3ZT9OAb0WIk1dayeauJTR6Ltuw2YTpPeBK5O2AaSpsqInULKpeSW-NwuGW-_oNDbiMnWfFzb3a4uW_g36-0MsMEtw6bBn1jPQtAk6YYp8JXMsmkENuoeNYcavD6E7I70\/s16000\/Infection%2520chain%2520%28Source%2520-%2520Cyble%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Infection chain (Source \u2013 Cyble)<\/figcaption><\/figure>\n<\/div>\n<p>Cyble analysts noted that the malware establishes <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> through Run registry keys and scheduled tasks immediately after deployment.<\/p>\n<p>The impact of Maranh\u00e3o Stealer extends beyond simple credential theft. By injecting a reflective DLL into browser processes, it bypasses <a href=\"https:\/\/cybersecuritynews.com\/strengthening-security-measures-in-digital-advertising-platforms-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a> like AppBound encryption to exfiltrate stored passwords, cookies, and browsing history from Chrome, Edge, Brave, Opera, and other Chromium-based browsers.<\/p>\n<p>Cyble researchers <a href=\"https:\/\/cyble.com\/blog\/inside-maranhao-stealer-node-js-powered-infostealer\/?__hstc=202258190.45506e6b59b92e29eb4a2c7692bd1d36.1757989462791.1757989462791.1757989462791.1&amp;__hssc=202258190.1.1757989462791&amp;__hsfp=2964922037\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the malware also targets cryptocurrency wallets\u2014Electrum, Exodus, Coinomi, and more\u2014making it a dual threat to both traditional account credentials and digital asset wallets.<\/p>\n<p>In addition to credential harvesting, Maranh\u00e3o Stealer conducts extensive system reconnaissance. It gathers hardware and network information via WMI queries such as <code>wmic os get Caption<\/code> and external API calls to <code>ip-api.com\/json<\/code>, profiling the operating system, CPU, disk space, and geographic location of the infected host.<\/p>\n<p>Screenshots captured through inline C# in PowerShell further augment the stolen intelligence, enabling threat actors to monitor user activity in real time.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>A closer examination of the infection mechanism reveals a multi-stage process designed for stealth and reliability.<\/p>\n<p>Upon execution of the Inno Setup installer, the main payload (<code>updater.exe<\/code>) is launched in <code>\/VERYSILENT<\/code> mode, suppressing any installation dialogs.<\/p>\n<p>Persistence is immediately secured with a registry modification:-<\/p>\n<pre class=\"wp-block-code\"><code>reg.exe ADD HKCUSoftwareMicrosoftWindowsCurrentVersionRun \/v updater \/t REG_SZ \/d \"C:Users&lt;username&gt;AppDataLocalProgramsMicrosoft UpdaterUpdater.exe\" \/f<\/code><\/pre>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiUFBvlwY7yUD0OSzEWuhRXd7GnUxiY-r70QEyYQzeo7a0Joub0YrHaPEis11ghwQJzZ7ex8sWRjtWNeUvm0CPJQkNZE16OCj53Djt6hxboj8ASRWBV7rD6gdpTjOHW5b4hETpStGcvM9AnMwDiBkYBI7lqFR7L8t9wk78ZzYl2m3kgp7JuLC9T_WNqrTM\/s16000\/Persistence%2520through%2520registry%2520%28Source%2520-%2520Cyble%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Persistence through registry (Source \u2013 Cyble)<\/figcaption><\/figure>\n<\/div>\n<p>Once the Run key is in place, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> marks its directory and files with hidden and system attributes through <code>attrib +h +s<\/code>, ensuring they remain obscured from casual inspection.<\/p>\n<p>The next phase involves spawning a helper process, <code>infoprocess.exe<\/code>, which injects a payload DLL directly into running browser processes.<\/p>\n<p>Using low-level Windows APIs\u2014<code>NtAllocateVirtualMemory<\/code>, <code>NtWriteProcessMemory<\/code>, and <code>CreateThreadEx<\/code>\u2014the malicious module is mapped into the target\u2019s memory space without touching the disk.<\/p>\n<p>This reflective injection technique not only evades antivirus scans but also runs inside the context of legitimate browser executables, making detection even more challenging.<\/p>\n<p>By combining social engineering, cloud-based distribution, and advanced injection tactics, Maranh\u00e3o Stealer exemplifies the evolving sophistication of modern credential stealers.<\/p>\n<p>Security teams should prioritize application control policies, endpoint monitoring for anomalous registry edits, and behavioral analysis to detect and block such stealthy threats in their early stages.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Free live\u00a0webinar\u00a0on new malware tactics from our analysts! Learn advanced detection techniques -&gt;\u00a0<a href=\"https:\/\/anyrun.webinargeek.com\/new-malware-tactics-cases-detection-tips-for-socs?cst=li_csn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Register for Free<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/maranhao-stealer-via-pirated-software-leveraging-cloud-hosted-platforms\/\">New Maranh\u00e3o Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/maranhao-stealer-via-pirated-software-leveraging-cloud-hosted-platforms\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Maranh\u00e3o Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials Since May 2025, a novel credential stealer dubbed Maranh\u00e3o Stealer has emerged as a significant threat to users of pirated gaming software. Distributed through deceptive websites hosting cracked launchers and cheats, the malware leverages cloud-hosted platforms to deliver trojanized installers that appear [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6946","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6946"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6946"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6946\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}