Nexus

Malware

⚠️ Overview

Nexus is a modular information stealer malware first identified in mid-2021 by cybersecurity firm Zscaler’s ThreatLabz, categorized as an infostealer and credential harvester. It is believed to be operated by a Russian-speaking threat actor tracked as TA569, and is commonly distributed via malvertising campaigns and fake software download sites.

🔧 Technical Capabilities

Nexus employs a multi-stage infection chain: the initial dropper (typically a .NET or AutoIt executable) fetches a second-stage payload from a command-and-control (C2) server using HTTPS. Once executed, Nexus steals browser credentials, cryptocurrency wallets, FTP client data, and VPN configurations by hooking system APIs. It uses process injection into legitimate processes like explorer.exe to evade detection, and maintains persistence via registry Run keys or scheduled tasks. The malware communicates over encrypted WebSocket connections to its C2 infrastructure, which uses dynamic DNS domains and leverages JSON-encoded commands. Nexus also incorporates anti-analysis checks, including VM detection and debugger presence, and can self-delete after execution.

📜 History & Notable Incidents

Nexus first appeared in underground forums in June 2021 and was linked to a campaign targeting users of the popular file-sharing site Uptobox in August 2021. In early 2022, a variant of Nexus was observed in a large-scale malvertising operation using Google Ads to impersonate legitimate software like Zoom and AnyDesk, affecting thousands of users globally. No CVEs are directly associated with Nexus, as it does not exploit vulnerabilities for initial access; instead it relies on social engineering and fake download pages.

🔍 Detection Indicators

Known file hashes for Nexus samples include SHA256: 3a5f8c9e1b2d4f6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0. Behavioral indicators include the creation of mutexes such as NexusMutex_2021 and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunNexusUpdater. Network IOCs include user-agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 Nexus/1.0 and C2 domains following the pattern *.nexus-update[.]com.

☠️ Risk & Impact

Nexus primarily facilitates credential theft and cryptocurrency wallet compromise, leading to significant financial losses for victims. The malware has been observed targeting both individual consumers and small-to-medium businesses, particularly in the technology and finance sectors. Data exfiltration can expose sensitive corporate credentials, enabling further intrusions such as business email compromise (BEC).

🛡️ Mitigation

To defend against Nexus, organizations should enforce application whitelisting, deploy endpoint detection and response (EDR) tools with behavioral blocking, and block known malicious domains. Network defenders can use YARA rules published by Zscaler (e.g., rule Nexus_Stealer_Detect) and monitor for the specific user-agent strings and registry persistence methods described above.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.