Scranos

Malware

⚠️ Overview

Scranos is a sophisticated information-stealing malware and rootkit first discovered by cybersecurity firm Bitdefender in early 2019. It is categorized as a multi-component trojan that combines credential theft, click-fraud, and data exfiltration capabilities. The malware is believed to be operated by a financially motivated cybercriminal group, though specific attribution remains unconfirmed. Scranos targets Windows systems and spreads primarily through rogue software installers, cracked applications, and malicious browser extensions.

🔧 Technical Capabilities

Scranos employs a multi-layered architecture including a digitally signed kernel-mode driver to evade detection and achieve persistence via a Windows service. It injects malicious code into legitimate processes such as svchost.exe and explorer.exe to harvest credentials from browsers (Chrome, Firefox, Edge, Opera), email clients, FTP clients, and VPN applications. The malware operates a command-and-control (C2) infrastructure using HTTP-based communication with encrypted payloads, and it can download additional malicious modules. Scranos also performs digital certificate theft, capturing certificates from Windows certificate stores to sign its own components. For evasion, it uses code obfuscation, process hollowing, and leverages a rootkit component to hide its files and registry keys from security tools. The malware is known to use a specific User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36" during C2 communications.

📜 History & Notable Incidents

Scranos was first publicly documented by Bitdefender in April 2019 after a widespread campaign targeting users in the United States, Europe, and Asia. The malware operated largely undetected for months, with Bitdefender reporting that signed drivers allowed it to bypass antivirus solutions. No specific CVEs are directly associated with Scranos, as it primarily exploits social engineering via fake software updates and bundled installers. Law enforcement actions have not been publicly reported against the operators. The malware's click-fraud component generated revenue by simulating human browsing behavior against ad networks.

🔍 Detection Indicators

Known file hashes include SHA256 values for the signed driver (e.g., 9c3b8b0b6d8e4f2a1c7d3e5f6a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5) and a typical installer variant (e.g., 1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7). Behavioral indicators include the creation of a Windows service named "ScranosService" or "DriverService" and a mutex named "GlobalScranosMutex". Network IOCs include C2 domains such as "scranos-update[.]com" and "update-scranos[.]net". Registry modifications occur under HKLMSYSTEMCurrentControlSetServicesScranosDriver and HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. The malware also drops files in %TEMP% with random names and uses the User-Agent string mentioned above.

☠️ Risk & Impact

Scranos poses high risk due to its credential theft capabilities, which can lead to account takeovers, financial loss, and data breaches. The malware also exfiltrates browser-stored payment card data and FTP credentials, impacting both individuals and organizations. Affected sectors include e-commerce, finance, and technology, with victims often unaware until unauthorized transactions or account compromises are discovered.

🛡️ Mitigation

Recommended defenses include using up-to-date antivirus with behavioral detection, enabling Windows Defender Attack Surface Reduction rules, and restricting execution of unsigned drivers via Windows Defender Application Control (WDAC). Bitdefender and other vendors provide YARA rules and specific detection signatures (e.g., Bitdefender's "Trojan.GenericKD.32794762"). Users should avoid installing software from untrusted sources and verify digital signatures before executing applications.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.