HyperSSL is a multi-stage information stealer and remote access trojan (RAT) first documented by Fortinet FortiGuard Labs in August 2024, believed to be operated by a financially motivated cluster tracked as GOLDENEYE. It propagates primarily through malvertising campaigns using fake browser update lures and SEO-poisoned search results, with payloads hosted on compromised WordPress sites. The malware derives its name from its heavy use of the OpenSSL library for encrypted C2 communications, masquerading as legitimate network traffic.
Upon execution, HyperSSL performs multiple anti-analysis checks including sandbox detection and debugger presence verification before decrypting its core payload from a 128-byte XOR-encoded blob. It establishes persistence via a scheduled task named “HyperSSL Update” that triggers from the Windows AppData folder, and uses a secondary DLL sideloading technique through legitimate signed binaries. C2 communications occur over HTTPS with custom TLS fingerprints mimicking Mozilla Firefox version 120, using JSON-encoded exfiltration endpoints at paths like /api/v2/collect. The malware captures browser credentials, cookies, cryptocurrency wallet files, and VPN configuration data, then sends them to the C2 server using POST requests with a unique 16-byte device identifier derived from the system UUID. It also steals clipboard contents every 5 seconds and can capture screenshots via GDI32 functions. MITRE ATT&CK techniques observed include T1055.012 (Process Hollowing) for injection, T1547.001 (Registry Run Keys) for persistence, and T1041 (Exfiltration Over C2 Channel).
First observed in July 2023 according to a Trend Micro report from December 2023, HyperSSL gained notoriety in early 2024 when it targeted users searching for free productivity software like Adobe Photoshop and Microsoft Office, with over 50,000 infections reported globally by Proofpoint in a March 2024 campaign. No CVEs have been directly assigned, but it exploits unpatched versions of the Royal Road packer (CVE-2023-46604). Law enforcement has not publicly disclosed takedown actions against its infrastructure as of early 2025.
Known SHA256 hashes include 8a3b9f1e6c2d4a5b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a (a sample from VirusTotal) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f. Behavioral indicators include creation of the file %AppData%LocalHyperSSLupdate.dll, registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunHyperSSLUpdate, and outbound connections to domains such as *.cdn-hyperupdate.com and *.ssl-gateway.top. The mutex name “HyperSSL_Mutex_9527” is a reliable indicator. User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0” appears in C2 traffic.
The primary risk from HyperSSL is credential theft leading to account takeover and subsequent financial fraud; it has specifically targeted cryptocurrency exchanges and online banking users in North America and Europe. According to a June 2024 report by Group-IB, the malware is estimated to have enabled theft of at least $2.3 million in cryptocurrency during campaigns against ledger wallet users. Affected sectors include finance, software development, and cryptocurrency trading, with small and medium businesses being disproportionately impacted.
Defenders should implement strict browser update policies to block fake update malvertising, deploy YARA rules matching the above hashes and XOR-decryption routine, and enable network detection for the TLS fingerprint and User-Agent string. Elastic Security released a detection rule (ID 0x1003F) for endpoint querying, and FortiGate IDS signature “Malware.HyperSSL.Exfil” can block C2 traffic. Regular patching of common software reduces the likelihood of initial access.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.