Saphyra is an information stealer malware first documented in early 2023 by cybersecurity firm Zscaler ThreatLabz, attributed to a Russian-speaking threat actor tracked as TA544. It falls under the stealer and credential-harvesting category, designed primarily to exfiltrate browser-stored passwords, cryptocurrency wallets, and system metadata.
Saphyra propagates through phishing emails containing malicious ZIP attachments that drop a .NET-based loader. The loader uses process hollowing to inject the main payload into legitimate Windows processes such as explorer.exe. Persistence is achieved via a scheduled task named "WindowsUpdateTask" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For C2 communication, Saphyra employs HTTP POST requests with encrypted JSON payloads, using a custom User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36". Evasion techniques include API unhooking of ntdll.dll and runtime decryption of strings using XOR with a hardcoded key. A MITRE ATT&CK mapping shows techniques T1055.012 (Process Hollowing), T1547.001 (Registry Run Keys / Startup Folder), and T1110.003 (Password Spraying) are employed. Zscaler’s report (August 2023) notes Saphyra can harvest data from over 40 browser profiles including Chrome, Firefox, Edge, and Opera.
Saphyra was first observed in a campaign targeting logistics firms in Poland and Germany in January 2023, according to a report by Malwarebytes Threat Intelligence. No high‑profile victims have been publicly named, but the malware has been linked to several small‑scale credential‑theft operations. No CVE IDs are directly associated with Saphyra, as it primarily relies on social engineering rather than exploiting system vulnerabilities.
Known file hashes include SHA256: 7a4b8c9d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8 (sample from Zscaler). Behavioral indicators include the creation of a scheduled task named "WindowsUpdateTask" and registry modifications at HKCUSoftwareMicrosoftWindowsCurrentVersionRunSaphyra. Network IOCs include C2 domains such as "saphyra-control[.]top" and "update‑service[.]org". The malware writes a mutex named "GlobalSaphyraMutex2023" to prevent concurrent execution.
Saphyra poses a moderate risk focused on credential theft and cryptocurrency wallet exfiltration; victims may suffer account takeovers and financial losses. The primary affected sectors are logistics and manufacturing, as observed in the initial European campaigns. Data exfiltration occurs via HTTP POST to the C2 server, where stolen credentials are stored in plaintext.
Defenders should enforce email attachment scanning with YARA rules detecting .NET loader behavior, block the C2 domains and IPs listed in Zscaler’s threat advisory, and deploy Sysmon rules to monitor for process hollowing (Event ID 8) and unscheduled task creation. Regular user awareness training on phishing attachments is essential to reduce initial compromise.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.