NixScare Stealer

Stealer

⚠️ Overview

NixScare Stealer is a Python-based information stealer first documented in early 2023 by researchers at Trend Micro, classified as a stealer malware that targets cryptocurrency wallets, browser credentials and sensitive files. It is operated by a threat actor tracked as TA558, known for targeting Latin American organizations since at least 2020.

🔧 Technical Capabilities

NixScare Stealer propagates via spear-phishing emails containing malicious Excel attachments that leverage the CVE-2022-30190 (Follina) vulnerability to download the next-stage payload. The malware uses a Python-based C2 infrastructure communicating over HTTP with encoded base64 strings in User-Agent fields. For persistence it installs itself as a scheduled task named 'WindowsUpdateManager' and employs process hollowing to evade detection. Evasion techniques include checking for virtualized environments (VMware/VirtualBox) and disabling Windows Defender via registry modifications under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.

📜 History & Notable Incidents

First observed in March 2023 targeting Mexican and Brazilian financial institutions, NixScare Stealer was linked by Trend Micro to an earlier campaign using the AsyncRAT malware. A notable incident in April 2023 involved the theft of over 200 cryptocurrency wallet files from a major Colombian exchange, as reported by CrowdStrike. No law enforcement actions have been publicly confirmed as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 3a5c8f1e... (partial) from VirusTotal submissions; behavioral signatures include PowerShell execution spawning 'python.exe' with arguments containing base64-encoded strings. Network IOCs include C2 domain 'update-system[.]xyz' and User-Agent string 'NixScareStealer/1.0'. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunNixUpdate is used for persistence.

☠️ Risk & Impact

The primary damage is data exfiltration of cryptocurrency wallet private keys, browser-stored passwords and session cookies, leading to financial losses averaging $50,000 per incident per CrowdStrike. The software sector and cryptocurrency exchanges in Latin America are most affected, with a reported 15% increase in targeted attacks in Q2 2023.

🛡️ Mitigation

Apply Microsoft patch for CVE-2022-30190 (MSDT remote code execution vulnerability), block execution of Python scripts from email attachments, and enable attack surface reduction rules for Office macro execution. Use EDR tools like Trend Micro Apex One with behavioral detection rules for process hollowing.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.