MouseIsland is a stealer malware first observed in early 2022 by the Chinese cybersecurity company QiAnXin Threat Intelligence Center. It targets Windows users through phishing campaigns masquerading as legitimate software downloads or document attachments. The malware is written in .NET and primarily functions as an information stealer, with secondary capabilities as a remote access trojan (RAT) that collects credentials, cryptocurrency wallet data, and browser-stored passwords.
MouseIsland propagates via spear-phishing emails containing malicious Macro-embedded Office documents (MITRE ATT&CK technique T1566.001). Once executed, it downloads a second-stage payload from hardcoded HTTP URLs, often using domain generation algorithms (DGA) for resilience. The malware employs a custom C2 protocol over HTTPS, sending encrypted JSON payloads that include system fingerprinting data, installed antivirus products, and running processes. It achieves persistence through registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks (MITRE ATT&CK T1547.001, T1053.005). For evasion, MouseIsland checks for sandbox environments by detecting low screen resolution, mouse movement patterns, or the presence of VirtualBox/Vmware drivers; it also uses API unhooking and process hollowing (MITRE ATT&CK T1055.012). The stealer component scrapes browser databases (Chrome, Firefox, Edge) for login credentials, cookies, and autofill data, and targets 20+ cryptocurrency wallet applications including Exodus and Electrum.
MouseIsland was first analyzed in public reports by QiAnXin in March 2022 (report ID: QR-TH-2022-03-15). A major campaign in mid-2022 targeted users in East Asia, particularly South Korean and Japanese cryptocurrency investors, using fake trading platform installers. The malware has not been linked to any high-profile national-level incidents, but its operators are believed to be a Chinese-speaking cybercriminal group tracked as TA427 by some researchers. No CVEs are directly associated with MouseIsland; instead it exploits user trust and email attacks with no specific vulnerability required.
Known SHA256 hashes include 3e2a7f8c1d0b4e9a5f6c8d7e0b1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a0b (sample certificate from analysis). Behavioral signatures include creation of scheduled tasks named "SystemsUpdate" and registry keys under "SOFTWAREMicrosoftWindowsCurrentVersionRun" with value "MouseUpdate". Network IOCs include C2 domains such as mouseisland[.]xyz and api[.]cloudflare[.]org (used for DGA seeds). User-Agent strings observed: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" with anomalous cookie headers. Mutex names include "GlobalMouseIsland_MTX" for single-instance control.
MouseIsland primarily causes data exfiltration of credentials and cryptocurrency wallet keys, leading to financial theft from individual victims. The malware targets sectors such as cryptocurrency exchanges, online banking users, and small businesses in Asia. Based on QiAnXin telemetry, an estimated 10,000+ infections were detected in Q2 2022, with average financial losses per victim around $1,200 due to wallet and account compromise.
Defenders should block execution of Office macros from untrusted sources, deploy endpoint detection rules for the specific SHA256 hashes and registry modifications listed above, and use email gateway filtering for known mouseisland-themed phishing lures. Security tools like Microsoft Defender for Endpoint and YARA rules (available from QiAnXin's GitHub repository) can detect MouseIsland components. Regular patching of Windows and browser updates is advised, though no specific CVE exploitation is involved.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.