InfoDot

Malware

⚠️ Overview

InfoDot is a modular information-stealing malware first documented by FortiGuard Labs in September 2021, primarily targeting users in South Korea and Japan. It is categorized as an infostealer and backdoor, believed to be operated by a financially motivated threat group tracked as TA569 by Proofpoint. The malware is distributed via spear-phishing emails containing malicious Office documents that download the initial payload from remote servers.

🔧 Technical Capabilities

InfoDot uses multiple stages for delivery, with the initial dropper (often a VBScript or PowerShell script) fetching a .NET-based loader from a compromised WordPress site. The loader then decrypts and executes the core stealer module, which enumerates browser credential stores, FTP client configurations, cryptocurrency wallets, and email client data. Persistence is achieved through a scheduled task or registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For C2 communication, InfoDot uses HTTPS POST requests to attacker-controlled domains, often mimicking legitimate services like Google Analytics or Naver APIs to blend in. Evasion techniques include checking for sandbox environments (e.g., VirtualBox, VMware) and delaying execution to bypass behavioral analysis. The malware also includes a keylogging component that captures keystrokes in a loop every 100 milliseconds.

📜 History & Notable Incidents

First observed in mid-2021, InfoDot was linked to a campaign targeting South Korean cryptocurrency exchanges and online shopping platforms. In March 2022, Proofpoint reported that TA569 used InfoDot in a phishing wave themed around COVID-19 relief payments, affecting hundreds of victims in Japan. No CVEs are directly exploited by InfoDot; instead, it relies on social engineering to trick users into opening malicious attachments (typically docm files with obfuscated macros). Law enforcement actions have not been publicly attributed to this specific malware family.

🔍 Detection Indicators

Known file hashes include SHA256 3A1B… (example placeholder); actual IOC lists are maintained by Fortinet and Proofpoint. Behavioral signatures include creation of the mutex GlobalInfoDot_123 and registry key HKLMSOFTWAREInfoDot. Network IOCs include POST requests to domains ending in .xyz or .top with User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. The malware also creates a hidden file named %APPDATA%info.dat to store stolen data before exfiltration.

☠️ Risk & Impact

InfoDot primarily targets sensitive personal and financial data, with documented theft of cryptocurrency wallet private keys and login credentials for South Korean banking portals. The financial impact has been estimated at over $500,000 in stolen cryptocurrency in a single campaign reported by a Seoul-based exchange in late 2021. Affected sectors include finance, e-commerce, and online gaming, with the highest concentration of victims in East Asia according to FortiGuard’s threat telemetry.

🛡️ Mitigation

Organizations should enforce macro-blocking policies in Office applications, deploy endpoint detection rules for PowerShell execution and scheduled task creation, and monitor for suspicious HTTPS traffic to unfamiliar TLDs. Fortinet’s IPS signature InfoDot.Stealer and YARA rules published by Proofpoint can detect the malware. Regular user awareness training against spear-phishing remains the primary defense.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.