Cyber Security

Eternity Group Hackers Offering New LilithBot Malware as a Service to Cybercriminals

The threat actor behind the malware-as-a-service (MaaS) called Eternity has been linked to new piece of malware called LilithBot.

“It has advanced capabilities to be used as a miner, stealer, and a clipper along with its persistence mechanisms,” Zscaler ThreatLabz researchers Shatak Jain and Aditya Sharma said in a Wednesday report.

“The group has been continuously enhancing the malware, adding improvements such as anti-debug and anti-VM checks.”

Eternity Project came on the scene earlier this year, advertising its warez and product updates on a Telegram channel. The services provided include a stealer, miner, clipper, ransomware, USB worm, and a DDoS bot.

LilithBot is the latest addition to this list. Like its counterparts, the multifunctional malware bot is sold on a subscription basis to other cybercriminals in return for a cryptocurrency payment.

Upon a successful compromise, the information gathered through the bot – browser history, cookies, pictures, and screenshots – is compressed into a ZIP archive (“report.zip”) and exfiltrated to a remote server.

The development is a sign that the Eternity Project is actively expanding its malware arsenal, not to mention adopting sophisticated techniques to bypass detections.

Articles You May Like

GSMA Plans End-to-End Encryption for Cross-Platform RCS Messaging
Google Working on Bringing Cross-Platform Chat Encryption ‘As Soon as Possible’ After iOS 18 Adds RCS Support
X-Class Solar Flare Erupts on the Sun, Earth-Directed CME Might Have Been Released
Adobe Introduces New Acrobat AI Assistant Student Plan at an Affordable Price
Vivo V40e Will Reportedly Launch in India by September-End With 5,500mAh Battery, Curved Display