Tuesday, March 4, 2025
HomeCyber CrimeSophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection with obfuscation and anti-analysis techniques, steals data from various browsers, applications, and cryptocurrency wallets. 

It operates as an Electron or NodeJS application, injecting code into vulnerable apps and communicating with C2 servers.

The malware’s FUD status is maintained through regular updates and deceptive tactics, making it a persistent threat to user privacy and security.

 Infection chain

Malicious actors are distributing a stealer disguised as a VR Chat NSFW application, where the “VRChatERPSetup.zip” archive contains an executable (AppSetup.exe) that utilizes a multi-stage download process.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

The initial script (start.bat) decodes a base64 string to download the actual stealer (Celestial) from a C2 server, which is then used to steal user data, as the malware is sold as a service on sellix.io with a configuration bot allowing customization through Telegram. 

Ads channel

Celestial Stealer, a JavaScript-based information stealer, is packaged as either an Electron application or a standalone NodeJS executable, which employs various anti-analysis techniques, such as obfuscation and runtime checks, to evade detection and hinder analysis. 

The stealer’s capabilities include checking for tampering, analyzing system date and platform, and executing malicious actions, while the obfuscated code is decrypted and executed, often leveraging PowerShell scripts to hide its activities and maintain persistence. 

Wrapper containing the PowerShell script as base64 string

It is malware that targets user data and cryptocurrencies by checking for virtual environments and terminating itself if detected and steals user credentials, browsing history, and crypto-wallets by looking for specific files and registry entries. 

It injects malicious payloads into Exodus and Discord applications to steal passwords, 2FA codes, credit card information, and more by communicating with its C2 server to download payloads and upload stolen data. 

Information being sent to C2 Server

By stealing information from a user’s device, it can steal files containing certain keywords, take screenshots, and kill targeted applications.

In earlier versions, it used legitimate services to exfiltrate data but now it sends data to its own C2 server. 

It injects code into Discord and Exodus applications and steals information from those platforms as well, while the Lite version removes most of these functionalities and focuses on data exfiltration and avoids systems with specific HWIDs.  

Exfiltration Mechanism

According to Trellix, it targets both Chromium and Gecko-based browsers and applications like Discord and Exodus, which evades detection through advanced anti-VM and anti-analysis techniques, and continuous updates ensure its persistence. 

By extracting sensitive data such as passwords and cookies, Celestial Stealer poses a significant risk to user security, highlighting the growing danger of JavaScript-based attacks that often disguise themselves as legitimate applications.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...