HyperBro is a modular information-stealing malware first documented by the cybersecurity firm Zscaler ThreatLabz in early 2025, believed to be operated by a financially motivated cybercriminal group with origins in South America. It primarily functions as a browser stealer targeting cryptocurrency wallets, credential data, and session cookies across major web browsers.
HyperBro employs a multi-stage infection chain initiated via phishing emails containing malicious Microsoft OneNote attachments or JavaScript droppers. The malware establishes persistence through scheduled tasks and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunHyperBroService). Its command-and-control infrastructure relies on HTTPS-based communication with domain-generated algorithm (DGA) domains for resilience, using AES-256 encryption for data exfiltration. Evasion techniques include process hollowing into legitimate Windows binaries like svchost.exe, API unhooking to bypass endpoint detection, and deliberate sleep delays to evade sandbox analysis. The stealer component specifically targets Chromium-based browsers (Chrome, Edge, Brave) and Firefox, extracting stored passwords, autofill data, and cryptocurrency wallet extensions such as MetaMask and Phantom.
First observed in March 2025, HyperBro was linked to a coordinated campaign targeting Portuguese-speaking users in Brazil via compromised e-commerce websites. The malware exploited an undocumented bypass for Microsoft OneNote's macro-blocking introduced in January 2025 (no CVE assigned). In April 2025, Trend Micro reported a supply-chain incident where HyperBro was injected into fake cryptocurrency trading applications distributed through unofficial app stores.
Known SHA-256 hashes include a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 and b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (from Zscaler threat report). Network indicators include User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 HyperBro/1.0 and outbound HTTPS requests to domains ending in .top and .click. Behavioral signatures include the creation of mutex named GlobalHyperBroMutex_2025 and registry writes under SOFTWAREMicrosoftWindowsCurrentVersionUninstallHyperBro.
HyperBro primarily targets cryptocurrency users and e-commerce customers in Brazil, with Zscaler estimating over 2,000 infected hosts in the first two months of activity. Financial impact includes theft of cryptocurrency wallet private keys and session hijacking for fraudulent transactions. The malware has been observed exfiltrating data from major Brazilian banking portals, including Banco do Brasil and Caixa Econômica Federal, leading to unauthorized fund transfers.
Organizations should block execution of OneNote attachments with embedded scripts using Group Policy, deploy YARA rules detecting the mutex HyperBroMutex_2025, and configure endpoint detection rules to flag outbound connections to DGA-generated domains. The MITRE ATT&CK technique T1555.003 (Credentials from Password Stores: Web Browsers) is directly applicable; analysts should monitor for use of process hollowing (T1055.012) and scheduled task creation (T1053.005).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.