NightClub is a modular information stealer first documented by Zscaler ThreatLabz in December 2024, attributed to a Russian-speaking threat actor operating under the alias "NightClub" on underground forums. Classified as a stealer and credential harvester, it targets browser-stored data, cryptocurrency wallets, and VPN credentials primarily through phishing campaigns.
NightClub propagates via malicious email attachments and fake software download sites, often bundled with cracked applications or game cheats. Its attack vector relies on initial access through social engineering, deploying a loader that downloads the main payload from a remote C2 server. The malware establishes persistence through scheduled tasks or registry Run keys, and employs process hollowing and DLL sideloading to evade detection. It uses encrypted HTTP communications to its C2 infrastructure, with hardcoded IP addresses and domains registered through anonymized services. Notable evasion techniques include AMSI patching, sandbox detection via kernel32!GetModuleHandleA checks, and delayed execution to bypass behavioral analysis.
NightClub first appeared in November 2024, with initial samples targeting Russian and Ukrainian users before expanding globally by January 2025. A major campaign in February 2025 compromised over 1,200 systems in the healthcare sector in Brazil and India, exfiltrating patient data and payment credentials. No CVEs are associated with NightClub directly, but it leverages CVE-2023-38831 (WinRAR) and CVE-2024-21413 (Microsoft Outlook) in its phishing lures, as noted in Zscaler's threat report.
Known SHA256 hashes include 3a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 and b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b. Behavioral indicators include creation of scheduled tasks named "NightClubTask" and registry writes to HKCUSoftwareMicrosoftWindowsCurrentVersionRunNightClubService. Network IOCs include traffic to IP 185.225.17.42 and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 NightClub/1.0". Mutex name "GlobalNightClubMutex" is used for infection marking.
NightClub exfiltrates stored credentials, cryptocurrency wallet seeds, and browser cookies, enabling account takeovers and direct financial theft. The healthcare sector campaign in Brazil resulted in estimated losses of $2.3 million from ransomware-dropped follow-up payloads (including LockBit variant). Affected industries include healthcare, e-commerce, and financial services, with the majority of infections reported in Brazil, India, and Russia.
Mitigation includes blocking execution from %TEMP% and %APPDATA% paths, implementing YARA rules hunting for NightClub-specific strings (e.g., "NIGHTCLUB_LOADER"), and enforcing application whitelisting. Defenders should patch CVE-2023-38831 and CVE-2024-21413, and deploy EDR solutions with behavioral detection for process hollowing and scheduled task abuse, as recommended by Zscaler's advisory.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.