The new version of Predator the Thief malware distributed through fake invoice documents aimed to steal sensitive user information.
The malware was first observed by Fortinet in July of 2018, the threat actors behind the malware family upgrading it in short intervals to make it more stealthy.
It is fully written in C/C++ and the malware sold in underground forums pricing between $35 to $80.
Fortinet observed a recent campaign of Predator the Thief with version 3.3.4 with enhanced capabilities.
The campaign uses multiple fake invoice documents that deliver Predator the Thief malware as the final payload.
Once the user opens the word document, AutoOpen macro runs the malware VBA script, which downloads three files using Powershell.
VjUea.dat – Legitimate version of AutoIt3.exe
SevSS.dat – Base64-encoded AutoIt script that uses certutil.exe for decoding
apTz.dat – RC4-encrypted Predator the Thief malware
The SevSS.dat script decoded by using the certutil.exe tool once decoded it uses legitimate AutoIt3.exe to run decoded AutoIt script. Then AutoIt script decrypts the apTz.dat, which is the final payload of Predator the Thief.
The malware sends the stolen information as a zip file, the zip file won’t get generated in the file system, instead, it adds the zip file directly from memory to the request data.
Communication with the C2 servers established through API and they are encrypted using basic base64 and RC4 algorithms.
The following are the information collected and sent to the C2 servers.
The malware continues to evolve and abuses legitimate tools to execute the payload and to avoid detection.
Cisco Systems has issued a critical security advisory for a newly disclosed command injection vulnerability…
A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from networks…
GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform that…
A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has been…
Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000 Series…
A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver Fox,…