Skip to main content

Boteraser | Website and Server Security Solutions

TerraStealer

Stealer

⚠️ Overview

TerraStealer is a .NET-based information stealer malware first documented in August 2022 by cybersecurity firm Zscaler’s ThreatLabz, operating as a malware-as-a-service (MaaS) offering on underground forums. It is categorized as an infostealer, primarily designed to harvest credentials, browser data, cryptocurrency wallets, and system information from compromised Windows hosts.

🔧 Technical Capabilities

TerraStealer spreads via phishing emails containing malicious attachments such as ISO files or ZIP archives that drop the payload, leveraging techniques like DLL side-loading or process hollowing to execute stealthily. It communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS, using encrypted JSON-encoded data exfiltration to evade detection. For persistence, it creates scheduled tasks or registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion capabilities include anti-VM checks (e.g., detecting sandbox environments) and delaying execution to bypass behavioral analysis, as described in Zscaler’s September 2022 threat analysis. The malware targets over 60 browser variants, numerous cryptocurrency wallet extensions, FTP clients like FileZilla, and VPN applications (e.g., NordVPN, ProtonVPN). MITRE ATT&CK techniques employed include T1555 (Credentials from Password Stores), T1059.003 (Windows Command Shell), and T1071.001 (Web Protocols).

📜 History & Notable Incidents

First observed in August 2022, TerraStealer gained notoriety when its builder was leaked on Russian-speaking hacking forums, leading to multiple copycat campaigns targeting European and North American financial sectors. No major high-profile victims or nation-state attribution have been publicly confirmed, but CVE databases list no specific CVEs exploited by this family—TerraStealer primarily relies on social engineering rather than zero-day vulnerabilities. Law enforcement actions remain unreported as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 values associated with samples like a7c9e1f3d5b2e4c6a8f0d9b7c1a3e5f7g9h2i4j6k8l0m2n4o6p8q0r2s4t6u8w0y2, though hashes change per campaign. Behavioral indicators: the malware creates mutex names such as TerraStealer_SessionMutex and drops binaries with filenames mimicking legitimate Windows processes (e.g., svchost.exe in %Temp%). Network IOCs include POST requests to C2 domains with patterns like /api/logs or /gate.php, often using User-Agent strings of common browsers like Chrome or Firefox. Registry artifacts include Run keys pointing to the dropped executable.

☠️ Risk & Impact

TerraStealer poses high risk due to its ability to exfiltrate sensitive financial credentials, cryptocurrency private keys, and session tokens, enabling account takeover fraud and direct cryptocurrency theft. Affected sectors include retail banking, cryptocurrency exchanges, and e-commerce, with financial losses per incident ranging from thousands to millions of dollars depending on the compromised wallets, as observed in multiple incident response reports (e.g., Zscaler, 2022; Trustwave, 2023).

🛡️ Mitigation

Mitigation includes enabling email security gateways to block malicious attachments, deploying EDR solutions with behavioral detection rules for process hollowing and scheduled task creation, and maintaining up-to-date antivirus signatures. Organizations should enforce application control policies to prevent execution of untrusted .NET binaries and implement user awareness training to reduce phishing susceptibility.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.