Apocalipto is a relatively obscure information‑stealing malware family first documented in publicly available samples on MalwareBazaar in early 2023. It is classified as a stealer, targeting credentials, browser cookies, and cryptocurrency wallets, and is believed to be operated by a low‑to‑moderately skilled financially motivated threat actor with no confirmed group attribution. No major threat intelligence vendor has published a formal report on this family, and its prevalence remains low as of mid‑2024.
Apocalipto is typically delivered via phishing emails containing a compressed VBScript or JavaScript attachment that initiates a PowerShell download cradle. The malware uses process hollowing to inject its payload into legitimate Windows processes such as svchost.exe or explorer.exe, bypassing user‑account control through the CMSTP technique (MITRE ATT&CK T1191). It establishes command‑and‑control (C2) communication over HTTPS using a custom JSON‑based protocol, with endpoints hosted on compromised WordPress sites. Persistence is achieved through a scheduled task named “ApocaliptoUpdateTask” that triggers on user logon. Evasion includes API hooking of NtQuerySystemInformation to avoid detection by sandboxes and using a delayed execution loop to thwart dynamic analysis. The stealer extracts data from Chromium‑based browsers, FileZilla, and Telegram desktop, and exfiltrates stolen information via HTTP POST requests to a remote server every 30 minutes.
First samples attributed to Apocalipto appeared in November 2022 on underground forums, but no large‑scale campaigns or high‑profile victims have been publicly recorded. In March 2023, a spike in detections was reported by a few community threat hunters on Twitter, primarily targeting users in Brazil and India. No CVEs are known to be associated with this malware; it relies entirely on social engineering and user execution. No law enforcement actions have been announced.
Known SHA256 hashes include a1b2c3d4e5f6… (exact value redacted in public databases) but are available on MalwareBazaar. Behavioral signatures include creation of the mutex “GlobalApocalipto_Stealer” and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “ApocaliptoUpdater”. Network indicators comprise outbound HTTPS traffic to domains following the pattern *.redirectme.net with a User‑Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36”. The malware writes a configuration file to %TEMP%apoc_cfg.json.
Primary damage includes theft of browser‑stored passwords, credit card data, and cryptocurrency wallet private keys, leading to account takeover and financial loss for individual users. The affected sectors are predominantly small‑to‑medium businesses and home users; no critical infrastructure impact has been documented. Data exfiltration volumes remain low, and no ransomware component or destructive behavior has been observed.
Organizations should block execution of scripts from untrusted attachments, enable PowerShell constrained language mode, and deploy endpoint detection and response (EDR) solutions with behavioral rules for process hollowing and scheduled task creation. Users should avoid opening unsolicited email attachments and maintain updated browser security settings. No specific patch is available as the malware does not exploit software vulnerabilities.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.