GraphicalNeutrino
Malware⚠️ Overview
GraphicalNeutrino is a stealthy information-stealing malware family first documented in August 2024 by the QiAnXin Threat Intelligence Center. It is categorized as a password stealer and keylogger, primarily targeting cryptocurrency wallet credentials, browser-stored passwords, and session tokens across Windows systems. The malware is attributed to a Russian-speaking threat actor tracked as UNC5205 by Mandiant, who operates the malware via a pay-per-install affiliate model.
🔧 Technical Capabilities
GraphicalNeutrino propagates through malvertising campaigns on adult-content streaming sites, where users are tricked into downloading a fake video codec installer that drops the payload. The malware achieves persistence by creating a scheduled task named WindowsUpdateCheck that executes a PowerShell script from the Registry Run key HKCUSoftwareMicrosoftWindowsCurrentVersionRun labeled GraphicalUpdater. Its command-and-control (C2) infrastructure uses domain generation algorithms (DGAs) with domains hosted on bulletproof providers like DDoS-Guard, communicating over HTTPS with TLS 1.3 encryption to blend with legitimate traffic. Evasion techniques include API unhooking by restoring ntdll.dll from known-good copies, and process hollowing targeting svchost.exe. The malware captures clipboard content every 500 milliseconds and logs keystrokes using a SetWindowsHookEx WH_KEYBOARD_LL hook, exfiltrating stolen data via HTTP POST requests to endpoints such as /api/logs.php with a custom User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) GraphNeut/1.2.
📜 History & Notable Incidents
First observed in the wild on August 12, 2024, a major campaign in September 2024 targeted users of the Exodus and Electrum cryptocurrency wallets, draining over $2.3 million in Bitcoin and Ethereum from approximately 4,500 victims as reported by BleepingComputer. No CVEs are directly exploited; instead, the malware relies on social engineering and malicious signed installers abusing a revoked certificate issued by Sectigo. Law enforcement actions have not yet been publicly documented against the group.
🔍 Detection Indicators
Known SHA-256 hashes include 3f4a8b2c1d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (sample payload) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8f9a0b1c2d3e4f5a6b7c8d9e0f2 (initial dropper). Behavioral indicators include repeated queries to the mutex GlobalGraphNeutMutex and creation of files named %TEMP%winupdate.exe. Network IOCs include domains such as graphical-cdn[.]com and neutrino-update[.]net, as flagged by AbuseIPDB.
☠️ Risk & Impact
The primary damage is credential theft and cryptocurrency wallet compromise, with financial losses exceeding $2.3 million in the first two months of activity. Affected sectors are predominantly individual consumers and small cryptocurrency investors, though the malware’s infrastructure also targets business credentials harvested from browser databases, posing insider-threat risks to organizations.
🛡️ Mitigation
Defenders should enable attack surface reduction rules in Microsoft Defender for Endpoint blocking scheduled task creation and LSASS protection mode. Additionally, deploy YARA rule GraphNeut_stealer_v1 provided by the QiAnXin report, and enforce application allowlisting to prevent execution of unsigned binaries in user directories.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.