NixScare Stealer
Stealer⚠️ Overview
NixScare Stealer is a Python-based information stealer first documented in early 2023 by researchers at Trend Micro, classified as a stealer malware that targets cryptocurrency wallets, browser credentials and sensitive files. It is operated by a threat actor tracked as TA558, known for targeting Latin American organizations since at least 2020.
🔧 Technical Capabilities
NixScare Stealer propagates via spear-phishing emails containing malicious Excel attachments that leverage the CVE-2022-30190 (Follina) vulnerability to download the next-stage payload. The malware uses a Python-based C2 infrastructure communicating over HTTP with encoded base64 strings in User-Agent fields. For persistence it installs itself as a scheduled task named 'WindowsUpdateManager' and employs process hollowing to evade detection. Evasion techniques include checking for virtualized environments (VMware/VirtualBox) and disabling Windows Defender via registry modifications under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
📜 History & Notable Incidents
First observed in March 2023 targeting Mexican and Brazilian financial institutions, NixScare Stealer was linked by Trend Micro to an earlier campaign using the AsyncRAT malware. A notable incident in April 2023 involved the theft of over 200 cryptocurrency wallet files from a major Colombian exchange, as reported by CrowdStrike. No law enforcement actions have been publicly confirmed as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 3a5c8f1e... (partial) from VirusTotal submissions; behavioral signatures include PowerShell execution spawning 'python.exe' with arguments containing base64-encoded strings. Network IOCs include C2 domain 'update-system[.]xyz' and User-Agent string 'NixScareStealer/1.0'. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNixUpdate is used for persistence.
☠️ Risk & Impact
The primary damage is data exfiltration of cryptocurrency wallet private keys, browser-stored passwords and session cookies, leading to financial losses averaging $50,000 per incident per CrowdStrike. The software sector and cryptocurrency exchanges in Latin America are most affected, with a reported 15% increase in targeted attacks in Q2 2023.
🛡️ Mitigation
Apply Microsoft patch for CVE-2022-30190 (MSDT remote code execution vulnerability), block execution of Python scripts from email attachments, and enable attack surface reduction rules for Office macro execution. Use EDR tools like Trend Micro Apex One with behavioral detection rules for process hollowing.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.