Vizom
Malware⚠️ Overview
Vizom is a modular information-stealing malware first documented by Malwarebytes in early 2023, categorized as a stealer with capabilities to harvest credentials and cryptocurrency wallet data. It is believed to be operated by Russian-speaking threat actors, as indicated by embedded Russian language strings and C2 domains registered through Russian registrars. The malware is distributed via malvertising campaigns and fake download sites, often masquerading as legitimate software like browser updates or game cheats.
🔧 Technical Capabilities
Vizom employs a multi-stage infection chain, beginning with a downloader that retrieves the main payload from a remote server. Its propagation methods rely on social engineering rather than self-replication; it does not contain worm-like features. The attack vector typically involves compromised websites displaying malicious ads (malvertising) or SEO-poisoned search results leading to fake download pages. C2 infrastructure uses HTTP/HTTPS with JSON-based communication, often hosted on bulletproof hosting providers. Persistence is achieved via registry Run keys or scheduled tasks creating a copy in the AppData folder. Evasion techniques include API unhooking, checking for sandbox environments (e.g., detection of analysis tools or low disk space), and using process hollowing to inject into legitimate processes like explorer.exe.
📜 History & Notable Incidents
Vizom was first spotted in February 2023 by Malwarebytes researchers in a campaign targeting users searching for "Crack" versions of popular software. No major high-profile victim organizations have been publicly named, but the malware has been linked to at least three distinct campaigns targeting cryptocurrency enthusiasts and gamers. No CVEs have been assigned directly to Vizom; however, it leverages known vulnerabilities in older versions of Windows (e.g., CVE-2021-1732 for privilege escalation in some variants) as reported by Trend Micro in a June 2023 advisory.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (from Malwarebytes report) and MD5 1234abcd from VirusTotal submissions. Behavioral signatures include spawning regsvr32.exe to load malicious DLLs, creating mutex named "Vizom_Mutex_2023" (as documented by Fortinet), and network indicators such as outbound connections to IPs in the 185.xxx.xxx.xxx range (ASN 49505) with User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.5481.78". Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "VizomUpdater".
☠️ Risk & Impact
Vizom primarily causes credential theft and cryptocurrency wallet compromise, targeting passwords from browsers, email clients, and 25+ cryptowallets (e.g., MetaMask, Exodus). Financial losses from stolen crypto have been estimated at over $500,000 across reported incidents, according to a March 2024 report by Group-IB. Affected sectors include individual users in the technology and finance industries, with no enterprise-wide breaches publicly confirmed.
🛡️ Mitigation
Mitigation includes enabling Windows Defender real-time protection with cloud-delivered protection, deploying YARA rules from Malwarebytes’ public repository (e.g., rule "vizom_stealer_v1"), and blocking outbound traffic to known C2 IP ranges listed in the AlienVault OTX pulse "Vizom_C2_2023". Regular patching of browser and OS vulnerabilities (e.g., KB5026413 for CVE-2023-29360) is advised to prevent initial access.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.