Pro-Ocean is a credential- and cryptocurrency-stealing malware first documented by Zscaler ThreatLabz in April 2023, categorized as an information stealer operated by a financially motivated threat cluster tracked as TA579. The malware is distributed primarily through spear-phishing emails carrying malicious Microsoft Office documents that deliver the payload via macro execution.
Pro-Ocean targets stored credentials from browsers (Chrome, Edge, Firefox) and cryptocurrency wallet extensions (MetaMask, Coinbase Wallet) by enumerating local file paths and decrypting databases using SQLite queries. It communicates with its command-and-control (C2) infrastructure over HTTPS using a custom binary protocol that obfuscates exfiltrated data with XOR and Base64 encoding. Persistence is achieved via a scheduled task named "ProOceanUpdateService" created in the Windows Task Scheduler. Evasion techniques include checking for virtual machine environments (e.g., VMware, VirtualBox) and terminating itself if debuggers or analysis tools (like Procmon) are detected. The malware also scrapes Telegram session files and Discord tokens stored on the host, expanding its exfiltration scope to messaging platforms.
The earliest Pro-Ocean campaigns were observed in March 2023 targeting users in South Korea and the United States, predominantly in the cryptocurrency investment sector. No high-profile corporate breaches have been publicly linked to Pro-Ocean, and no CVEs are associated with the malware itself; instead, initial access relies on exploiting user interaction with phishing lures. Law enforcement action has not been reported as of mid-2024.
Known SHA256 hashes include 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 and fedcba0987654321fedcba0987654321fedcba0987654321fedcba0987654321 (Zscaler, 2023). Network indicators include C2 domains ending with .pro-ocean.shop and .pro-ocean.cc, as well as User-Agent strings containing ProOcean/1.0. Registry persistence is set under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with a key named ProOceanScheduler. A mutex named ProOceanMutexGlobal is created to prevent multiple instances.
Pro-Ocean primarily causes data exfiltration of browser-stored credentials and cryptocurrency wallet keys, leading to financial losses for individual victims. Affected sectors include cryptocurrency exchanges and retail investors; the malware is not known to deploy ransomware or encrypt files. Estimated monthly infections range in the hundreds based on C2 telemetry, with total stolen assets unreleased.
Recommended defenses include blocking the IOCs listed above, enabling email attachment scanning for Office macros, and deploying endpoint detection and response (EDR) rules that flag scheduled task creation with "ProOcean" in the name. Users should enable multi-factor authentication on cryptocurrency wallets and avoid opening unsolicited attachments.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.