Go to listing page

Rilide Stealer Evolves to Target Chrome Extension Manifest V3

Rilide Stealer Evolves to Target Chrome Extension Manifest V3
A new version of Rilide Stealer has been discovered, which targets Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, and Opera to steal sensitive data and cryptocurrency. The updated version shares similarities with malware tracked as CookieGenesis.

Campaigns identified in the wild

  • Trustwave researchers identified over 1,300 phishing websites distributing the new version of Rilide Stealer along with other harmful malware such as Bumblebee, IcedID, and Phorpiex. 
  • These websites impersonated various entities, including banks, government services, software companies, delivery services, and crypto token airdrops.  

What campaigns look like?

  • In one campaign, attackers leveraged a PowerPoint phishing lure and a fake Palo Alto GlobalProtect plugin to target corporate users.
  • Another campaign contained a fake P2E games installer advertised on Twitter that was used to drop Rilide and Redline Stealer.
  • A third campaign focused on banking users in Australia and the U.K, stealing cryptocurrencies from wallets by employing AngelDrainer scripts.

Malware updates

  • While it shares similarities with its predecessor discovered in April, the latest Rilide version exhibits a higher level of sophistication through code obfuscation and adaptation to the Chrome Extension Manifest V3.
  • It includes a new command called ‘screenshot_rules,’ letting attackers capture active tab screenshots at regular intervals. 
  • Another feature of the variant is the ability to exfiltrate stolen data such as credit card details to a Telegram channel.

Conclusion

It’s worth noting that the source code of the Rilide extension was leaked in February, raising the possibility that threat actors other than the original group are picking up the development efforts. Meanwhile, organizations are advised to leverage the IOCs and understand the nature and attack scope of the latest version in order to deploy the required security measures.
Cyware Publisher

Publisher

Cyware