Wave Stealer

Stealer

⚠️ Overview

Wave Stealer is an information-stealing malware first documented by Cyble researchers in November 2023, targeting Windows systems to harvest browser credentials, cryptocurrency wallets, and session tokens. Operated by an unknown threat actor, it belongs to the infostealer category and is distributed via phishing emails containing malicious ZIP archives or JavaScript downloaders.

🔧 Technical Capabilities

Wave Stealer uses process injection (MITRE ATT&CK T1055.001) to inject its payload into legitimate processes like explorer.exe, and achieves persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It exfiltrates stolen data over HTTP POST requests to hardcoded C2 domains, encrypting data with AES-256 before transmission. The malware employs anti-analysis techniques such as checking for sandbox artifacts (e.g., known VM processes) and delaying execution to evade dynamic analysis. It can capture credentials from browsers like Chrome, Edge, and Firefox by reading SQLite databases, and targets over 40 cryptocurrency wallet extensions including MetaMask and Exodus. The C2 infrastructure uses domain generation algorithms (DGA) with seeds based on the victim’s system date, making takedown efforts more difficult.

📜 History & Notable Incidents

First observed in October 2023, Wave Stealer was linked to a campaign targeting cryptocurrency users in Southeast Asia, with a significant spike in activity in January 2024 involving dozens of fake trading platform pages. No high-profile corporate victims or law enforcement actions have been publicly reported; however, the malware has been observed exploiting CVE-2023-36025 (Windows SmartScreen bypass) in some initial access vectors as noted in a Trend Micro advisory.

🔍 Detection Indicators

Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (wave_stealer_sample.exe) and a mutex name GlobalWvStlrMutex. Network IOCs include communication with domains ending in .top and .xyz on port 443, using a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) WaveStealer/1.0. Registry persistence keys are created under HKCU...RunWindowsUpdate.

☠️ Risk & Impact

Wave Stealer causes direct financial loss by exfiltrating cryptocurrency wallet private keys and draining accounts, with estimated damages exceeding $500,000 based on Cyble’s January 2024 report. The primary impact is on individual cryptocurrency investors and small crypto-exchanges, with the malware also stealing session cookies that can lead to account takeovers on social media platforms.

🛡️ Mitigation

Defenders should enable Windows Defender Attack Surface Reduction (ASR) rules to block process injection, deploy YARA rules matching the hardcoded DGA patterns, and block the known C2 domains and hashes. Regular user awareness training against phishing with malicious ZIP files is critical, and organizations should enforce application control to prevent unauthorized executables from running.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.