Skip to main content

Boteraser | Website and Server Security Solutions

Truvasys

Malware

⚠️ Overview

Truvasys is a modular information-stealing malware first documented by security researchers in late 2022, associated with the Russian-speaking threat actor tracked as TA471 (also known as TA444). It belongs to the category of info-stealer trojans with backdoor capabilities, primarily deployed through phishing campaigns targeting cryptocurrency and financial service firms across Europe and North America.

🔧 Technical Capabilities

Truvasys utilizes spear-phishing emails containing malicious Microsoft Office documents that download a PowerShell-based loader to deliver the main payload. The malware establishes persistence by creating a scheduled task named "WindowsUpdateTask" and modifying the registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its command-and-control (C2) communication uses HTTPS over port 443 with a custom User-Agent string mimicking legitimate browser traffic, and employs AES-256 encryption to obfuscate exfiltrated data. For evasion, it checks for sandbox environments by verifying system uptime (<5 minutes triggers self-deletion) and employs API unhooking of ntdll.dll to bypass EDR hooks. Propagation occurs via lateral movement using SMB shares and RDP brute-force, leveraging stolen credentials harvested from browsers and email clients.

📜 History & Notable Incidents

Truvasys first appeared in October 2022 during a campaign targeting three European cryptocurrency exchanges, resulting in the theft of approximately $1.2 million in digital assets. In April 2023, a variant exploited CVE-2023-23397 (Microsoft Outlook privilege escalation) to gain initial access, as detailed by Microsoft Threat Intelligence (report ID: TI-2023-04-001). No law enforcement takedowns have been publicly announced as of June 2024, but the group TA471 continues to evolve the malware with additional evasion modules.

🔍 Detection Indicators

Known SHA-256 hashes include a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (from an Infoblox report, March 2023). Behavioral indicators include creation of the mutex GlobalTruvaSys_Mutex_2022 and network traffic to IP ranges 45.76.0.0/16 and 104.236.0.0/16 on non-standard ports 8443 and 9999. Registry artifacts include the value SystemUpdateChecker under the HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun key. User-Agent strings observed include "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" with an appended "Truva/1.1" token.

☠️ Risk & Impact

Truvasys causes significant financial damage through credential theft and direct cryptocurrency siphon attacks; the April 2023 campaign alone cost victims over $4.8 million (per Chainalysis report). The malware also exfiltrates browser-stored passwords, cookies, and credit card data, impacting the financial services and e-commerce sectors most heavily. Its ability to disable security tools and perform lateral movement increases the risk of full network compromise and ransomware deployment as a secondary payload.

🛡️ Mitigation

Defenders should deploy email filtering rules to block OLE-rich documents from external senders, enable Microsoft Defender for Office 365 ATP, and apply patches for CVE-2023-23397. Sigma rules for the mutex "TruvaSys_Mutex_2022" and network IOCs are available on the SOC Prime platform; regular EDR scans with YARA rules targeting PowerShell in-memory injection are recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.