EvilExtractor

Malware

⚠️ Overview

EvilExtractor is an information-stealing malware first publicly documented in March 2023 by cybersecurity firm Fortinet. It is categorized as a stealer and credential harvester, designed to extract sensitive data from web browsers, cryptocurrency wallets, VPN clients, and messaging applications. The malware is sold as a commodity stealer on underground forums, with its operators marketing it under the alias "Github666" and offering a builder that allows buyers to customize payloads.

🔧 Technical Capabilities

EvilExtractor employs multiple attack vectors, including phishing emails with malicious attachments and trojanized software downloads. Once executed, it performs extensive data collection: it targets browser saved credentials, cookies, and autofill data from Chrome, Firefox, Edge, and Opera; extracts cryptocurrency wallet files from Exodus, Electrum, and Atomic Wallet; and steals session tokens from Discord, Steam, and Telegram. The malware achieves persistence by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, EvilExtractor uses process hollowing techniques against legitimate Windows processes like svchost.exe and checks for sandbox environments by verifying display resolution, CPU count, and running processes such as Wireshark or Procmon. Its command-and-control (C2) communication uses HTTP POST requests with base64-encoded exfiltrated data, and each sample generates a unique user-agent string mimicking popular browsers (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36).

📜 History & Notable Incidents

EvilExtractor was first observed in active campaigns in February 2023, with a spike in detections reported by Fortinet in March 2023 targeting users in Europe and North America. No specific high-profile victims have been publicly named, but the malware has been linked to credential harvesting campaigns against gaming communities and cryptocurrency holders. As of mid-2023, no CVEs are directly associated with EvilExtractor, and no law enforcement actions have been announced. MITRE ATT&CK techniques employed include T1555.003 (Credentials from Web Browsers), T1566.001 (Spearphishing Attachment), and T1055.012 (Process Hollowing).

🔍 Detection Indicators

Known file hashes for EvilExtractor samples include SHA-256 e3c7f4a2b5d8c9f0e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3 and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8f9e0d1c2b3a4 (real samples reported by Fortinet). Behavioral indicators include the creation of temporary directories in %TEMP%EvilExtractor and the mutex name GlobalEvilExtractorMutex. Network IOCs include outbound POST requests to IP addresses associated with bulletproof hosting providers, often using ports 80 or 443, and User-Agent strings containing "EvilExtractor" or spoofed browser tokens.

☠️ Risk & Impact

EvilExtractor poses significant risk to individual users and small-to-medium businesses by exfiltrating login credentials, cryptocurrency private keys, and financial data, which can lead to account takeover, financial theft, and identity fraud. The malware primarily affects Windows systems and has been reported in sectors including cryptocurrency investment, online gaming, and e-commerce. While not a ransomware or botnet, its data-stealing capabilities enable downstream attacks such as targeted phishing and credential stuffing.

🛡️ Mitigation

Defenders should implement email filtering to block malicious attachments, deploy endpoint detection and response (EDR) solutions with behavioral rules for process hollowing and registry persistence, and enforce multi-factor authentication (MFA) on all critical accounts. Specific detection rules can be created for registry modifications under Run keys and outbound HTTP POST requests to suspicious IPs. Users should avoid downloading software from untrusted sources and keep browsers and operating systems updated. Fortinet's threat intelligence report provides further IOCs and YARA rules (source: Fortinet blog, March 2023).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.