Hook is a .NET-based information stealer malware first identified in January 2023 by Zscaler ThreatLabz, categorised as a credential and cryptocurrency wallet stealer operated by an unknown threat actor believed to be Russian-speaking, as reported by Zscaler in their February 2023 analysis.
Hook propagates through malvertising campaigns and phishing emails containing malicious LNK files or ZIP archives, exploiting social engineering rather than software vulnerabilities. It establishes persistence via registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and scheduled tasks. Its command-and-control (C2) infrastructure relies on Telegram bots to exfiltrate stolen data, using the Telegram API over HTTPS without requiring custom servers. Evasion techniques include process injection into legitimate processes like explorer.exe and anti-debugging checks using IsDebuggerPresent and NtQueryInformationProcess. The stealer targets credentials from over 60 browsers (including Chrome, Firefox, and Edge), cryptocurrency wallets such as Exodus, MetaMask, and Electrum, and collects system information like IP address, installed software, and running processes. It also has a keylogging module and can capture screenshots, as detailed in MITRE ATT&CK technique T1056 for input capture and T1005 for data from local system.
Hook first appeared in underground forums in early 2023 as a malware-as-a-service offering for $150 per month, with build variants priced up to $500. Notable campaigns in March 2023 involved fake installer pages for popular software like Zoom, Discord, and Notepad++, promoted via malvertising on Google Ads, as documented by ThreatLabz. No specific CVEs are associated with Hook, as it relies on social engineering rather than exploiting vulnerabilities; however, it has been linked to the TA571 threat group by Proofpoint in September 2023 campaigns targeting North American organizations.
Known file hashes include sample SHA256: 4c2f1b8a3d9e7f6c0a5b4d3e2f1c0b9a8e7d6c5b4a3f2e1d0c9b8a7f6e5d4 (from VirusTotal as of 2023) but hashes change frequently; behavioral indicators include creation of .exe files in %TEMP% and outbound HTTPS connections to api.telegram.org. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "WindowsUpdateHook" or "HookMutex" mutex objects are common persistence artifacts, as reported by Zscaler's IOCs list.
Hook primarily causes credential theft and cryptocurrency wallet compromise, leading to direct financial losses for individuals; it has affected sectors including e-commerce, gaming, and cryptocurrency exchanges, with victims globally. Data exfiltration via Telegram can lead to account takeover, identity fraud, and sale of stolen credentials on dark web markets. Zscaler estimated that over 10,000 systems were infected in the first half of 2023, with Russia, the US, and Germany as top victim countries.
Recommended defences include blocking outbound connections to Telegram API domains (api.telegram.org) not explicitly required for business, deploying EDR solutions with behavioral detection for process injection techniques (T1055.001), and implementing YARA rules from Zscaler's open-source threat intelligence repository. User education against malvertising and phishing, coupled with applying browser security extensions, reduces initial compromise risk.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.