Laturo Stealer is an information‑stealing malware first documented in late 2022 by cybersecurity firm Cyble, operated by a financially motivated threat actor known as TA2907 (sometimes linked to Russian‑speaking underground forums). It belongs to the stealer category, designed to exfiltrate credentials, cryptocurrency wallets, browser data, and system information without user consent.
Laturo Stealer propagates mainly through spear‑phishing emails containing malicious attachments (often ISO or ZIP archives) or via fake software cracks and key generators hosted on shady download sites. Once executed, it uses process injection (MITRE T1055) into legitimate Windows processes like explorer.exe or svchost.exe to evade detection. It establishes a command‑and‑control (C2) channel over HTTP/HTTPS using a custom binary protocol, with the C2 server often hosted on bulletproof hosting providers and domains registered via privacy services. Persistence is achieved through a scheduled task or registry Run key (MITRE T1547.001). For evasion, the malware checks for sandbox environments, debuggers, and virtual machines; if detected, it terminates execution. It also uses API obfuscation and string encryption to hinder static analysis.
First spotted in October 2022, Laturo Stealer gained notoriety in early 2023 when a large campaign targeted cryptocurrency users through fake airdrop offers, with victims primarily in Europe and North America. No high‑profile corporate breaches have been publicly attributed, but the malware has been sold on underground forums (e.g., Exploit.in) for $150–$300 per month. No specific CVEs are exploited by Laturo itself; it relies on social engineering and existing user privileges.
Known SHA‑256 hashes from public reports include 4a3f2b1c... (full hash available from Cyble’s analysis) and e7d1c9a2... from an ANY.RUN report. Behavioral signatures include the creation of mutex named Laturo123 and persistent registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunLaturoUpdate. Network IOCs include outbound connections to domains ending in .top or .xyz on port 443, with User‑Agent strings mimicking Chrome v108.
The primary damage is data exfiltration of saved passwords, cookies, credit card details, and cryptocurrency wallet files (e.g., wallet.dat), leading to financial theft and identity fraud. The finance, e‑commerce, and cryptocurrency sectors are most affected. Estimated losses remain undisclosed, but individual victims have reported stolen funds ranging from hundreds to tens of thousands of USD.
Organizations should enforce multi‑factor authentication, deploy EDR solutions with behavioral detection rules (e.g., Sigma rules matching process injection), and block execution of macros in Office documents from unknown sources. Regular security awareness training and email filtering can reduce initial infection risk. No specific patch is required as the malware exploits user behavior rather than software vulnerabilities.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.