Obscene
Malware⚠️ Overview
Obscene is a sophisticated information-stealing malware family first documented by the cybersecurity firm Proofpoint in June 2020, operating as a commodity stealer targeting credential and session-token data from web browsers and cryptocurrency wallets. It is categorized as a Trojan Stealer and is primarily distributed through malvertising campaigns and fake download portals controlled by a Russian-speaking threat actor tracked as TA2712 (also known as CryptoBot).
🔧 Technical Capabilities
Obscene employs a multi-stage infection chain: initial payloads are delivered via malicious JavaScript or PowerShell scripts dropped from fake browser-update landing pages. The malware harvests credentials, cookies, and autofill data from Chrome, Firefox, and Edge browsers, and specifically targets Exodus, Electrum, and Atomic cryptocurrency wallets by scanning for wallet.dat files and configuration directories. It establishes persistence by creating scheduled tasks under the name "ObsceneUpdate" and modifies the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For command-and-control (C2) communication, it uses HTTPS POST requests to hardcoded IP addresses and domains frequently hosted on bulletproof hosting providers in Ukraine and Russia, encoding exfiltrated data with a custom XOR-based cipher. Evasion techniques include process hollowing (injecting into legitimate processes such as svchost.exe), delaying execution to avoid sandbox analysis by checking for the presence of VMware and VirtualBox drivers, and disabling Windows Defender via PowerShell commands.
📜 History & Notable Incidents
Obscene was first reported by Proofpoint in June 2020, attributed to a single actor (TA2712) who also developed the "CryptoBot" fake cryptocurrency exchange. In October 2021, a large campaign distributed Obscene via malvertising on the Gootloader infrastructure, targeting users searching for legitimate software such as Zoom and TeamViewer. No CVEs have been directly associated with Obscene itself, as it relies on social engineering and pirated software vectors. No law enforcement actions against the group have been publicly reported as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes for Obscene samples include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (a placeholder; actual hashes vary per campaign). Network IOCs include domains such as *obscene-test[.]com* and IP addresses in the 185.165.29.0/24 range. Registry artifacts include the key HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallObsceneUpdate and a mutex named "GlobalObsceneMut". User-Agent strings in C2 traffic often mimic "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
☠️ Risk & Impact
Obscene primarily targets individual cryptocurrency enthusiasts and small-to-medium businesses that store wallet credentials in browsers, causing direct financial theft through emptied cryptocurrency wallets. Stolen credentials can also enable account takeover attacks on email and cloud services. The malware has been observed predominantly in English-speaking and European countries, with the energy and e-commerce sectors the most affected according to Proofpoint telemetry.
🛡️ Mitigation
Defenders should enforce browser isolation policies, block execution of scripts from untrusted domains, and deploy endpoint detection rules (e.g., Sigma rules for process hollowing via svchost.exe). The MITRE ATT&CK techniques most applicable are T1055.012 (Process Hollowing), T1547.001 (Registry Run Keys), and T1059.001 (PowerShell). Organizations should also implement application whitelisting for cryptocurrency wallet executables and maintain up-to-date antivirus signatures (Proofpoint TRAP, CrowdStrike Falcon).
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.