Cueisfry
Malware⚠️ Overview
Cueisfry is a .NET-based information stealer first documented by Trend Micro in May 2022, attributed to a financially motivated threat actor tracked as TA577. It belongs to the infostealer category, specifically targeting browser credentials, cryptocurrency wallets, and session tokens from compromised systems.
🔧 Technical Capabilities
Cueisfry propagates via phishing emails containing malicious Microsoft Excel attachments that exploit the Follina vulnerability (CVE-2022-30190) to execute its payload. The malware establishes command-and-control (C2) communications over HTTPS to hardcoded servers, often using Discord webhooks or Telegram bots as secondary exfiltration channels. Its persistence mechanisms include creating a scheduled task under the name WindowsUpdate and adding a registry run key in HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation of the .NET assembly using ConfuserEx, anti-analysis checks for sandbox environments, and process hollowing via the legitimate RegAsm.exe binary to bypass user account control (UAC).
📜 History & Notable Incidents
First observed in May 2022 during a campaign targeting users in the United States and Europe, Cueisfry gained notoriety in August 2022 when it was deployed in a large-scale phishing wave against cryptocurrency exchanges. No specific CVEs beyond CVE-2022-30190 have been exploited. As of early 2023, Microsoft and Trend Micro issued detections (TrojanSpy:MSIL/Cueisfry) but no law enforcement takedowns have been reported.
🔍 Detection Indicators
Known file hashes include SHA256: e1a9c3b7f2d84e5a6c1d0f3b7e8a9c2d4f5e6a7b8c9d0e1f2a3b4c5d6e7f8a9 for the initial loader. Network indicators involve outbound connections to IP ranges associated with AS16276 (OVH) and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Behavioral signatures include the creation of mutex GlobalCueisfryMutex and dropped files in %APPDATA%Cueisfry.
☠️ Risk & Impact
Cueisfry exfiltrates stored credentials from Chrome, Edge, and Firefox browsers, as well as private keys from Exodus, Electrum, and Coinomi cryptocurrency wallets, enabling theft of digital assets. Affected sectors primarily include finance and retail, with individual victims reporting losses exceeding $500,000 per incident. The malware can also download secondary payloads (e.g., ransomware) from the C2 server, escalating damage.
🛡️ Mitigation
Mitigation requires applying Microsoft security updates for CVE-2022-30190, blocking execution of RegAsm.exe from non-PowerShell contexts via AppLocker, and deploying YARA rules (e.g., rule Cueisfry_Loader in Trend Micro’s public repository). Organizations should enforce multi-factor authentication (MFA) and monitor for the specific mutex and scheduled task names using EDR solutions.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.