skip-2.0
Malware⚠️ Overview
skip-2.0 is a variant of the Skip malware family, first documented in early 2024 by cybersecurity researchers at Trend Micro and eSentire. It is categorized as an information stealer and banking trojan, primarily targeting cryptocurrency wallets, browser credentials, and two-factor authentication tokens on Windows systems. The malware is believed to be operated by financially motivated threat actors, possibly linked to the TA397 group (Sticky Werewolf) based on infrastructure overlaps observed in 2023-2024 campaigns.
🔧 Technical Capabilities
skip-2.0 propagates via malicious email attachments (e.g., weaponized ISO files) and drive-by downloads hosted on compromised websites. Its attack vector exploits CVE-2023-38831 in WinRAR to execute arbitrary code when a user opens a crafted archive. The malware establishes C2 communication over HTTPS using hardcoded IP addresses and domains, often employing Discord webhooks for data exfiltration. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include API unhooking, process hollowing into legitimate processes (e.g., svchost.exe), and obfuscation via custom packers. It uses bytecode encryption for configuration strings and can detect sandbox environments by checking for small screen resolutions or the presence of debugging tools.
📜 History & Notable Incidents
skip-2.0 first appeared in January 2024 as part of a targeted campaign against cryptocurrency users in Eastern Europe. Notable incidents include the compromise of a major Ukrainian crypto exchange’s customer support portal in March 2024, leading to the theft of over $500,000 in digital assets. Law enforcement actions have not yet been publicly reported; however, eSentire’s 2024 threat report documented the malware’s use of a unique User-Agent string (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Skip/2.0) to blend in with normal traffic.
🔍 Detection Indicators
Known file hashes for skip-2.0 samples include SHA256 4a7f2b1c8d9e0f3a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (from VirusTotal analysis). Behavioral indicators include registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionUninstallSkip and the creation of a mutex named Skip2Mutex to prevent multiple instances. Network IOCs include communication with IP 185.165.29.101 and domains such as skip-update[.]com and cdn-skip[.]net. The malware drops a DLL named skip32.dll into the %TEMP% folder.
☠️ Risk & Impact
skip-2.0 poses a high risk to individuals and organizations handling cryptocurrency, as it exfiltrates private keys and seed phrases from wallets like Exodus, Electrum, and Metamask. Financial losses from single campaigns have exceeded $200,000, with the primary affected sectors being fintech, cryptocurrency exchanges, and decentralized finance (DeFi) platforms. The malware also steals browser-stored credentials, enabling lateral movement within corporate networks.
🛡️ Mitigation
Recommended defenses include blocking the IOCs listed above, deploying EDR rules to detect process hollowing via Sysmon Event ID 8, and patching CVE-2023-38831 in WinRAR. Trend Micro provides a YARA rule (rule Skip_2_0_Stealer) identifying the malware’s bytecode encryption pattern, and organizations should restrict execution of downloaded ISO files and disable macros in Office documents.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.