- Apr 21, 2017
- 971
- 360
- 136
This looks like a very serious problem for windows users. It supports basically all popular windows browsers, steals passwords saved on your browser (as well as other info). It is somehow able to inject DLL and install itself onto windows computers. This malware CNC suite was offered for sale on the deep web I think.
https://threatpost.com/oski-data-stealing-malware-north-america-china/151856/
Oski’s theft tactics involve extracting credentials using man-in-the-browser (MitB) attacks by hooking the browser processes using DLL injection, Sood told Threatpost. It also extracts credentials from registry, passwords from the browser SQLite database and stored session cookies of all stripes, including crypto-wallet cookies from Bitcoin Core, Ethereum, Monero, Litecoin and others.
https://threatpost.com/oski-data-stealing-malware-north-america-china/151856/