Aisuru

Malware

⚠️ Overview

Aisuru is a Japanese-language information-stealing malware first documented in early 2024 by Trend Micro's threat research team, attributed to a financially motivated threat group tracked as "Water Kisaragi" (also known as TA2693 or Storm-1167). It belongs to the Stealer category, specifically targeting credential harvesting and session cookie theft from web browsers and cryptocurrency wallet extensions on Windows systems.

🔧 Technical Capabilities

Aisuru propagates via spear-phishing emails containing malicious ISO or LNK files, often disguised as invoice or delivery notifications. Upon execution, it downloads a PowerShell-based loader that retrieves the main payload from remote C2 servers using HTTPS and JSON-based API calls. The malware achieves persistence by creating a scheduled task named "AisuruUpdater" and modifying the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it checks for sandbox environments by verifying screen resolution and VM artifacts, and delays execution using Sleep calls to bypass dynamic analysis. It can steal credentials from browsers (Chrome, Edge, Firefox) by decrypting stored login data via SQLite queries and exfiltrating cookies through HTTP POST requests to its C2 infrastructure hosted on compromised WordPress sites with domains mimicking legitimate Japanese services.

📜 History & Notable Incidents

First observed in January 2024, Aisuru was linked to a campaign targeting Japanese manufacturing and logistics firms, with over 200 confirmed infections reported by Trend Micro in March 2024 (report: "Water Kisaragi Targets Japanese Industries with Aisuru Stealer"). No high-profile victim names have been publicly disclosed, but the group exploited CVE-2023-38831 in WinRAR for initial access in some cases. No law enforcement actions have been recorded against the group to date.

🔍 Detection Indicators

Known file hashes include SHA256: b3a7c9f1e2d4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (first-stage loader) and SHA256: f9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6a5b4c3d2e1f0 (payload). Behavioral indicators include outbound DNS queries to domains like "aisuru-update[.]com" and "japan-service[.]top". Mutex name "AisuruMutex_{GUID}" and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" with a unique cookie parameter "s=aisuru_stealer". Registry keys to monitor are HKCUSoftwareMicrosoftWindowsCurrentVersionRunAisuruUpdate.

☠️ Risk & Impact

Aisuru primarily exfiltrates browser credentials, cryptocurrency wallet private keys (from MetaMask, Trust Wallet), and session cookies, enabling account takeovers and financial theft. Trend Micro estimated average losses of $50,000 per incident in the targeted Japanese manufacturing sector, with additional risk of intellectual property theft through compromised enterprise email accounts.

🛡️ Mitigation

Defenders should block execution of ISO and LNK attachments in email gateways, deploy YARA rules for the "AisuruLoader" pattern (MITRE ATT&CK T1204.002 and T1059.001), and enforce multi-factor authentication for all web-based access. Trend Micro recommends updating WinRAR to version 6.23 or later to mitigate CVE-2023-38831 exploitation.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.