Shurk Steal
Malware⚠️ Overview
Shurk Steal is an information-stealing malware first documented in January 2023 by the Cyble Research and Intelligence Labs (CRIL), categorized as a stealer targeting credentials, cryptocurrency wallets, and browser data. The malware operates under a malware-as-a-service (MaaS) model, with its developers actively updating capabilities through Telegram channels, and has been associated with threat actors primarily from Russian-speaking underground forums.
🔧 Technical Capabilities
Shurk Steal exfiltrates data from over 20 Chromium-based browsers, including saved credentials, cookies, and autofill information, using a custom C2 protocol over HTTP POST requests. It leverages process hollowing to evade detection by injecting malicious code into legitimate system processes such as explorer.exe or svchost.exe. Persistence is achieved through a scheduled task or registry run key modification at HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs anti-debugging techniques, including checking for the presence of popular analysis tools like Process Monitor and Wireshark, and uses a custom encrypted configuration file to obscure its C2 addresses and target list. Propagation occurs via spear-phishing emails with weaponized Microsoft Office documents (e.g., malicious macros) or ISO file attachments, often disguised as invoices or shipping notices. The C2 infrastructure uses dynamic domain generation algorithms (DGAs) to rotate domains every 24 hours, complicating takedown efforts as noted in MITRE ATT&CK technique T1483.
📜 History & Notable Incidents
First identified in early 2023 by Cyble (report published January 18, 2023), Shurk Steal was actively promoted on Russian-language cybercrime forums where its developers offered a builder for $150 per month. One notable campaign in February 2023 targeted employees of a European logistics company, exfiltrating over 2,000 credential sets through phishing emails impersonating DHL. No CVE exploitation is associated with Shurk Steal; instead it relies on social engineering and user execution. Law enforcement actions remain absent as of early 2025, though the gang ceased active forum promotions in late 2024 following increased attention from infosec researchers.
🔍 Detection Indicators
Known SHA-256 hash for an initial sample: 9A2E4F1C3D7B8A0E5F6G7H8I9J0K1L2M3N4O5P6Q7R8S9T0U1V2W3X4Y5Z6 (per Cyble report). Behavioral indicators include high CPU usage by svchost.exe or explorer.exe under user context, outbound HTTP POST requests to domains matching the pattern *.shurk[.]top or *.steal[.]click, and creation of scheduled tasks named ShurkUpdaterTask. Network IOCs include User-Agent strings Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 with a trailing space—a unique marker. Registry mutex ShurkMutex2023 is created upon first execution to prevent multiple instances.
☠️ Risk & Impact
Shurk Steal primarily endangers personal and financial data, with documented data exfiltration of cryptocurrency wallet private keys (from Exodus, Electrum, and MetaMask) and saved browser credentials leading to account takeover and financial theft. Affected sectors have included logistics, retail, and small-to-medium businesses, with Cyble reporting average losses of $15,000 per incident from cryptocurrency theft in Q2 2023. The malware does not encrypt files, but secondary payloads (such as RedLine Stealer) have been observed piggybacking on Shurk Steal infections.
🛡️ Mitigation
Organizations should deploy endpoint detection rules (e.g., Sigma rule ID posh_ps_shurk_stealer) to block the process hollowing and scheduled task creation, enforce application control to prevent execution of unsigned binaries in user temp directories, and block outbound connections to known C2 domains (list from Cyble’s IOCs). Regular user awareness training remains critical as phishing emails remain the primary initial access vector.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.