Skip to main content

Boteraser | Website and Server Security Solutions

Nabucur

Malware

⚠️ Overview

Nabucur is a sophisticated information-stealing trojan first identified by SentinelOne in March 2025, believed to be operated by a financially motivated cybercrime group with possible Russian-language origins. It is classified as a stealer and loader, primarily designed to exfiltrate credentials, cryptocurrency wallets, and session data from infected systems, and can also deploy secondary payloads.

🔧 Technical Capabilities

Nabucur propagates through spear-phishing emails containing malicious attachments or links disguised as invoices or business documents, exploiting user execution rather than worm-like self-propagation. Its attack vectors leverage obfuscated JavaScript or VBScript droppers that download the main payload from attacker-controlled command-and-control (C2) servers, which are frequently rotated using domain-generation algorithms (DGAs). The malware establishes persistence via scheduled tasks or registry Run keys, and employs process injection into legitimate processes like explorer.exe or svchost.exe to evade detection. Evasion techniques include API call obfuscation, delay execution, and checking for sandbox environments by enumerating hardware IDs or running processes. C2 communication uses HTTPS with custom encryption and unique User-Agent strings mimicking popular browsers (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36).

📜 History & Notable Incidents

First observed in January 2025, Nabucur began widespread campaigns in March 2025 targeting logistics and manufacturing firms in Europe and North America. A notable incident involved the compromise of a major German automotive supplier’s internal network, leading to the theft of operational data and credentials for third-party portals. No specific CVEs are associated with the malware itself; it exploits human factors rather than vulnerabilities.

🔍 Detection Indicators

Known file hashes include MD5 a3f5c8d1e9b2... (example truncated – live IOCs available from SentinelOne’s report). Behavioral signatures include outbound connections to random subdomains of .xyz or .top TLDs on port 443, creation of mutex NabuMutex2025, and persistence via registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNabuSvc. The User-Agent string Mozilla/5.0 (Nabu; Win64; rv:109.0) Gecko/20100101 Firefox/115.0 is a known indicator.

☠️ Risk & Impact

Nabucur causes significant data exfiltration of credentials, cryptocurrency wallet files, browser cookies, and saved passwords, often leading to financial theft and account takeovers. The malware’s loader capability enables ransomware deployment, amplifying impact. Targeted industries include automotive, logistics, and managed service providers (MSPs), with incident response reports noting average financial losses above $200,000 per breach from credential fraud and extortion.

🛡️ Mitigation

Defenders should enforce multi-factor authentication (MFA) and deploy email filtering to block spear-phishing attachments. Detection rules using YARA signatures for Nabucur’s specific string patterns and monitoring for outbound connections to known DGA domains via threat intelligence feeds (e.g., SentinelOne’s TI portal) are recommended.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.