Thursday, February 27, 2025
HomeLinux malwareStealthWorker Brute-force Malware Attack on Windows & Linux Platform Via Hacked...

StealthWorker Brute-force Malware Attack on Windows & Linux Platform Via Hacked E-commerce Websites

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new brute-force malware called StealthWorker that attack Windows & Linux platform via compromised E-commerce websites to steals personal information and payment data.

This Stealthy malware written in Golang language which is very rarely used by malware authors and this language already being used by Mirai botnet develop module.

In this case, E-commerce websites are being compromised by attackers using an embedded skimmer, before that they gain access to their target’s backend.

Threat actors achive this target by exploiting the vulnerabilities in the Content Management System (CMS) or abusing the plugin vulnerabilities.

StealthWorker malware Infection Process

Researchers initially analysing the command and control server (5.45.69[.]149) where they found the /storage directory hosting 5 samples that are intended to brute force the open source admin tool called PhPMyAdmin.

Previous version of this malware only targeted the windows platform but this new version also serves payload binaries to compromised the Linux platform.

Later researchers start analysing one of the sample “PhpMyAdminBrut_Windows_x86.exe” where they found another IP which leads to same web panel login and open directory with the variety of new samples.

These open directories are contains new filenames that indicate to targeting IoT devices with ARM and Mips architectures.

During the execution of StealthWorker malware creates a scheduled execution to make sure the malware stay persist even after victims reboot the system.

In Further analysis researchers use the IDA python script and find the malicious function that is used by this malware and the functions are clearly indicate that the malware targets the various platforms and services including cpanel, Mysql, SSH, Joomla. FTP Etc.

According to Fortinet research, “As we have seen in this new StealthWorker campaign, the malware developers have also taken further steps to increase their rate of success by also being able to infect a wider range of platforms.”

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Brutespray – Port Scanning and Automated Brute Force Tool

StegCracker – Brute-force Utility to Uncover Hidden Data Inside Files

New Hacking Group Outlaw Distributing Botnet to Scan The Network & Perform Cryptocurrency-Mining & Brute-Force Attack

Troldesh Ransomware Spreading Via Weaponized Word Document and RDP Brute-force Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade...

Poseidon Mac Malware Hiding Within PKG Files to Evade Detections

A recent discovery by cybersecurity researchers has revealed that the Poseidon malware, a macOS-targeting...