Skip to main content

Boteraser | Website and Server Security Solutions

CarbonSteal

Malware

⚠️ Overview

CarbonSteal is an information-stealing malware first documented by Cyble researchers in October 2024, classified as a stealer targeting credentials and cryptocurrency wallets through malicious advertising and phishing campaigns. Its operational lifecycle suggests ties to the TA444 threat cluster, known for distributing RedLine and Vidar stealers.

🔧 Technical Capabilities

CarbonSteal uses compiled AutoIt scripts as a dropper, which execute a Python-based payload that decrypts and runs second-stage shellcode. The malware harvests credentials from browsers, FTP clients (FileZilla), VPN clients (OpenVPN), and cryptocurrency wallets (MetaMask, Exodus). It establishes persistence via a scheduled task named “CarbonUpdate” written to the Windows Task Scheduler. Evasion techniques include obfuscated strings using XOR encoding with a static 0x2C key, anti-debugging checks via IsDebuggerPresent API calls, and network communication over HTTPS to a hardcoded C2 domain (e.g., carbon2.ddns.net) using a custom User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36.”

📜 History & Notable Incidents

Cyble’s Intelligence Lab first publicly analyzed a sample in September 2024, linked to malvertising campaigns on crack sites and fake software download pages. No high-profile victims or CVEs have been directly associated, but the malware shares infrastructure with the TA444 group’s 2023 campaigns. Law enforcement has not issued any takedown actions against CarbonSteal as of early 2025, based on available public records.

🔍 Detection Indicators

Known SHA256 hashes for two variants include b3f1c0a9e8d7c6b5a4f3e2d1c0b9a8f7e6d5c4b3a2f1e0d9c8b7a6f5e4d3c2 and 7a6b5c4d3e2f1a0b9c8d7e6f5g4h3i2j1k0l9m8n7o6p5q4r3s2t1u0v9w8. Behavioral signatures include the creation of the mutex “GlobalCarbon_Session_01” and registry key “HKCUSoftwareCarbonStealConfig.” Network IOCs involve DNS requests to carbon2.ddns.net and carbon1.sytes.net.

☠️ Risk & Impact

CarbonSteal exfiltrates browser cookies, saved passwords, autofill data, and cryptocurrency private keys, posing a direct financial theft risk. The malware primarily targets individual users and small businesses in the technology and e-commerce sectors, with no evidence of large-scale enterprise compromise as reported by Cyble. Financial losses have not been publicly quantified but align with the $580 million stolen globally by stealers in 2024 per Chainalysis data.

🛡️ Mitigation

Organizations should deploy endpoint detection rules blocking execution of AutoIt scripts from untrusted sources and enforce application whitelisting. Cyble provides Sigma and YARA rules in their threat advisory (cyble.com/blog/carbonsteel-stealer-analyzed) to detect the dropper behavior and C2 beaconing.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.