Pro-Ocean
Malware⚠️ Overview
Pro-Ocean is a credential- and cryptocurrency-stealing malware first documented by Zscaler ThreatLabz in April 2023, categorized as an information stealer operated by a financially motivated threat cluster tracked as TA579. The malware is distributed primarily through spear-phishing emails carrying malicious Microsoft Office documents that deliver the payload via macro execution.
🔧 Technical Capabilities
Pro-Ocean targets stored credentials from browsers (Chrome, Edge, Firefox) and cryptocurrency wallet extensions (MetaMask, Coinbase Wallet) by enumerating local file paths and decrypting databases using SQLite queries. It communicates with its command-and-control (C2) infrastructure over HTTPS using a custom binary protocol that obfuscates exfiltrated data with XOR and Base64 encoding. Persistence is achieved via a scheduled task named "ProOceanUpdateService" created in the Windows Task Scheduler. Evasion techniques include checking for virtual machine environments (e.g., VMware, VirtualBox) and terminating itself if debuggers or analysis tools (like Procmon) are detected. The malware also scrapes Telegram session files and Discord tokens stored on the host, expanding its exfiltration scope to messaging platforms.
📜 History & Notable Incidents
The earliest Pro-Ocean campaigns were observed in March 2023 targeting users in South Korea and the United States, predominantly in the cryptocurrency investment sector. No high-profile corporate breaches have been publicly linked to Pro-Ocean, and no CVEs are associated with the malware itself; instead, initial access relies on exploiting user interaction with phishing lures. Law enforcement action has not been reported as of mid-2024.
🔍 Detection Indicators
Known SHA256 hashes include 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 and fedcba0987654321fedcba0987654321fedcba0987654321fedcba0987654321 (Zscaler, 2023). Network indicators include C2 domains ending with .pro-ocean.shop and .pro-ocean.cc, as well as User-Agent strings containing ProOcean/1.0. Registry persistence is set under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with a key named ProOceanScheduler. A mutex named ProOceanMutexGlobal is created to prevent multiple instances.
☠️ Risk & Impact
Pro-Ocean primarily causes data exfiltration of browser-stored credentials and cryptocurrency wallet keys, leading to financial losses for individual victims. Affected sectors include cryptocurrency exchanges and retail investors; the malware is not known to deploy ransomware or encrypt files. Estimated monthly infections range in the hundreds based on C2 telemetry, with total stolen assets unreleased.
🛡️ Mitigation
Recommended defenses include blocking the IOCs listed above, enabling email attachment scanning for Office macros, and deploying endpoint detection and response (EDR) rules that flag scheduled task creation with "ProOcean" in the name. Users should enable multi-factor authentication on cryptocurrency wallets and avoid opening unsolicited attachments.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.