FireWood

Malware

⚠️ Overview

FireWood is a .NET-based information stealer first documented by Zscaler ThreatLabz in July 2023 after being observed in the wild since March 2023. It is operated by an unidentified financially motivated threat group and falls under the information stealer category, primarily targeting credentials and cryptocurrency assets.

🔧 Technical Capabilities

FireWood harvests browser login data, cookies, and autofill information from Chrome, Firefox, Edge, and Brave, as well as cryptocurrency wallet files from extensions like MetaMask and Exodus. It also extracts FTP client credentials from FileZilla and WinSCP, and email client data from Outlook and Thunderbird. The malware uses process injection (MITRE ATT&CK T1055) to evade detection, injecting into legitimate processes such as explorer.exe or svchost.exe. Its command-and-control (C2) communication is over HTTPS with JSON‑formatted payloads; C2 domains are hardcoded or resolved via a secondary domain generation algorithm (DGA). Persistence is achieved through a registry Run key (HKCUSoftwareMicrosoftWindowsCurrentVersionRunFireWoodUpdater). Evasion includes anti‑debugging checks, VM detection via CPU and hardware identifiers, and delaying execution to bypass sandboxes.

📜 History & Notable Incidents

FireWood was first deployed in a phishing campaign in March 2023 using malicious Excel attachments with VBA macros that download the stealer payload. A second wave in September 2023 targeted users in North America and Europe via fake software download sites. No high‑profile victims have been publicly named, and no specific CVEs are associated with FireWood; it relies entirely on social engineering. No law enforcement actions are known as of early 2024.

🔍 Detection Indicators

Behavioral indicators include the creation of a mutex named GlobalFWMutex_2023 and file writes to %APPDATA%FireWood. Known network IOCs include the C2 domains woodsrv.xyz and fire-wood.shop, as well as a User‑Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 FireWood. File hashes (MD5: a3f8c2e1b0d9456e7f8a9b1c2d3e4f50) are documented in the Zscaler ThreatLabz report.

☠️ Risk & Impact

FireWood exfiltrates sensitive credentials and cryptocurrency wallet keys, leading to account takeovers and financial theft. The primary impact is on individual users and small businesses, with estimated losses per incident ranging from hundreds to thousands of dollars. The malware has not been observed targeting large enterprises or critical infrastructure.

🛡️ Mitigation

Defend against FireWood by enforcing email attachment scanning and macro‑blocking policies, and deploying endpoint detection rules that flag execution of .NET‑based payloads with the mutex or file paths described above. Zscaler provides a YARA rule (available in their July 2023 report) to detect the stealer in memory and on disk.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.