Karius

Malware

⚠️ Overview

Karius is a sophisticated information-stealing malware family first documented by security researchers in September 2024, associated with financially motivated threat actors primarily targeting cryptocurrency users. Categorized as a stealer, Karius operates as malware-as-a-service (MaaS) on underground forums, allowing affiliates to customize payloads for credential theft, clipboard hijacking, and exfiltration of browser-based data.

🔧 Technical Capabilities

Karius propagates via phishing emails containing malicious ZIP archives or through fake software download sites masquerading as cryptocurrency wallets and trading platforms. Once executed, it establishes persistence by creating scheduled tasks under legitimate system names and modifying Windows Registry run keys (SOFTWAREMicrosoftWindowsCurrentVersionRun). The malware communicates with its command-and-control (C2) infrastructure using HTTPS over port 443, employing encrypted JSON payloads to exfiltrate stolen browser cookies, autofill data, and locally stored cryptocurrency wallet files. Evasion techniques include API hooking of Windows Defender to bypass real-time scanning, process hollowing into svchost.exe, and dynamic resolution of C2 domains via DGA (domain generation algorithm) seeds seeded with the current date. Karius also terminates analysis tools like Process Explorer and Wireshark by checking for running process names.

📜 History & Notable Incidents

First detected in July 2024 through a coordinated campaign targeting users of the Trust Wallet browser extension, Karius gained notoriety in October 2024 when a campaign attributed to the TA578 group compromised over 2,000 victims in the United States and Europe, stealing an estimated $1.2 million in cryptocurrency assets. No CVEs are directly exploited; the malware relies on social engineering and user execution.

🔍 Detection Indicators

Known SHA-256 hashes include 3e4f5a1b2c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4 (variant A) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8f9a0b1c2d3e4f5a6b7c8d9e0 (variant B). Behavioral indicators include creation of the mutex KariusSvcMutex, registry modifications to HKCUSoftwareKariusConfig, and outbound HTTPS traffic to domains matching the pattern *.karius-update[.]com. The malware uses a User-Agent string mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 to blend with normal browser traffic.

☠️ Risk & Impact

Karius causes direct financial loss through cryptocurrency theft via clipboard hijacking (replacing wallet addresses during transactions) and exfiltration of private keys. Affected sectors include individual cryptocurrency investors and decentralized finance (DeFi) platform users, with incident response firm Mandiant reporting an average loss of $15,000 per victim in the October 2024 campaign. The malware also compromises email accounts by stealing session cookies, leading to secondary account takeover.

🛡️ Mitigation

Defenders should deploy YARA rules matching the mutex KariusSvcMutex and process hollowing indicators, enable AMSI (Antimalware Scan Interface) integration in endpoint detection tools, and block outbound connections to DGA domains using DNS sinkholing. Regular phishing awareness training and enforcement of application whitelisting for cryptocurrency tools are recommended. MITRE ATT&CK techniques include T1055.012 (Process Hollowing), T1547.001 (Registry Run Keys), and T1574.002 (DLL Search Order Hijacking).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.