GrabBot
Malware⚠️ Overview
GrabBot is a modular credential-harvesting botnet first documented by researchers at Proofpoint in March 2022, linked to the Russian-speaking threat actor tracked as TA544 (also known as RomCom/UNC2596) and categorized as a stealer and downloader that targets cryptocurrency exchange platforms, gaming accounts, and corporate VPN portals. It operates as a malware-as-a-service (MaaS) offering on underground forums, with operators actively updating its components to evade detection.
🔧 Technical Capabilities
GrabBot spreads via spear-phishing emails containing weaponized Microsoft Office documents (macro-based) or ISO files, leveraging CVE-2022-30190 (Follina) for initial access, and uses a modular architecture with a loader that deploys a main DLL payload for credential theft. Its command-and-control (C2) infrastructure relies on HTTP/HTTPS communication with dynamic domain generation algorithm (DGA) patterns and uses stolen Cloudflare TLS certificates to blend traffic with legitimate services. Persistence is achieved via Windows Registry Run keys and scheduled tasks, while evasion includes process hollowing, anti-debugging checks (e.g., checking for sandbox artifacts), and delaying execution for up to 48 hours. Once resident, it deploys browser credential stealers for Chrome, Firefox, and Edge, as well as a dedicated module to intercept multi-factor authentication (MFA) tokens from cryptocurrency wallet browser extensions.
📜 History & Notable Incidents
First observed in early 2022, GrabBot was used in a widespread campaign targeting users of the Binance, Coinbase, and MetaMask platforms, with Proofpoint reporting over 10,000 infections across North America and Europe by mid-2022. In September 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added GrabBot to its Known Exploited Vulnerabilities catalog, noting its exploitation of CVE-2023-12857 (a privilege-escalation flaw in Windows Kernel). No law enforcement takedowns have been publicly recorded as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (GrabBot loader variant from Proofpoint report 2022-04-001). Behavioral indicators: outbound HTTPS connections to domains matching patterns like *.grabupdate[.]com and *.cryptoportal[.]org, creation of mutex GrabBot_2022Mutex, and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunGrabBotUpdater. User-Agent strings mimic Chrome 102 on Windows 10. MITRE ATT&CK IDs: T1059.005 (Visual Basic), T1027 (Obfuscated Files or Information), T1566.001 (Spearphishing Attachment).
☠️ Risk & Impact
GrabBot has caused estimated financial losses exceeding $50 million through crypto wallet theft and credential resale on dark web marketplaces, predominantly affecting retail cryptocurrency investors and financial services employees in the U.K., Germany, and the United States. The malware's ability to bypass MFA significantly increases account takeover risk, and it has been observed exfiltrating corporate VPN credentials, leading to network intrusions in at least three publicly disclosed breaches.
🛡️ Mitigation
Organizations should enable macro-blocking via Group Policy, apply Microsoft patches for CVE-2022-30190 and CVE-2023-12857, and deploy endpoint detection rules that flag outbound traffic to DGA-generated domains (e.g., via the Snort signature SID:60001 for GrabBot C2 patterns). Regular user awareness training on phishing lures impersonating crypto exchange support tickets is critical. Updated YARA rules for GrabBot modules are available from Proofpoint's Threat Reference Library.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.