nitlove
Malware⚠️ Overview
Nitlove is a stealer malware first documented in late 2022 by cybersecurity researchers at Zscaler's ThreatLabz. It belongs to the infostealer category, specifically designed to harvest credentials, cryptocurrency wallets, and browser data from infected systems. The malware is believed to be operated by a financially motivated threat actor, though no official group attribution has been publicly confirmed. Nitlove is often distributed through cracked software installers and malicious email attachments, as noted in Zscaler's October 2023 report.
🔧 Technical Capabilities
Nitlove employs a multi-stage infection chain: the initial dropper, typically a .NET compiled binary, downloads a secondary payload from a command-and-control server using HTTP GET requests. The malware achieves persistence by creating a scheduled task named "NitloveUpdater" that launches the payload at system boot. It performs data exfiltration over HTTPS to hardcoded C2 domains, encoding stolen data in Base64 and wrapping it in JSON. Evasion techniques include checking for debugger presence via the NtQueryInformationProcess API and sleeping for up to 120 seconds before executing malicious routines. Nitlove specifically targets browser credential stores (Chrome, Firefox, Edge) by reading the SQLite database files, and it can enumerate cryptocurrency wallet extensions such as MetaMask and Exodus by scanning for folder names under the user's AppData directory.
📜 History & Notable Incidents
Zscaler first identified Nitlove in November 2022 during a routine sandbox analysis of a lure document titled "Invoice_20221114.docm." A notable campaign in early 2023 saw the malware distributed through fake download pages for popular software like Adobe Photoshop and Discord Nitro, affecting approximately 1,500 systems in North America and Europe according to Zscaler telemetry. No CVEs are directly associated with Nitlove; it relies on social engineering rather than exploit chains. Law enforcement actions have not been publicly reported.
🔍 Detection Indicators
Observed file hashes include SHA256: 9f8c7a3b2e1d4f5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8. Behavioral signatures include the creation of the scheduled task "NitloveUpdater" and outbound HTTPS traffic to domains such as nitlove-c2[.]xyz and update-nitlove[.]com. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun have been observed, though persistence is primarily via scheduled tasks.
☠️ Risk & Impact
Nitlove causes data exfiltration of browser credentials and cryptocurrency wallet data, potentially leading to account takeovers and direct financial theft. Affected sectors include individual consumers and small businesses, as the malware primarily spreads through cracked software and phishing. Financial losses per incident are estimated in the hundreds to low thousands of dollars based on stolen cryptocurrency, according to Zscaler's threat assessment.
🛡️ Mitigation
Defenders should implement application whitelisting to block execution of untrusted .NET binaries, enable PowerShell logging to detect suspicious script activity, and deploy endpoint detection rules that monitor for the "NitloveUpdater" scheduled task creation. Zscaler's threat feed provides YARA rules and network IOCs for automated blocking. No specific patches are available as Nitlove does not exploit software vulnerabilities.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.