Photo of Smartphone Screen With App Icons
© mama_mia/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Cybersecurity researchers have discovered a sophisticated new info-stealing malware called Exela targeting social media and browser applications.

In a blog post published on Tuesday, Cyble Research and Intelligence Labs (CRIL) said Exela is an open-source info-stealer used to harvest sensitive information from compromised Windows devices.

The malware can pilfer private information, like login credentials, credit card details, keystrokes, etc. It exfiltrates this data using Discord Webhooks.

Exela is designed to run when a compromised device starts up. The malware goes through multiple layers of obfuscation, which makes it “exceptionally challenging for anyone attempting to reverse engineer or comprehend the underlying code,” Cyble’s blog post said.

Exela Targets Social Media, Web Browsers

While the malware primarily targets the social media platform Discord, Exela is also capable of stealing data from Chromium-based browsers like Brave, Google Chrome, Microsoft Edge, and others, as well as Mozilla.

It can even harvest data from gaming platforms and popular social media platforms like Instagram, Twitter, and TikTok, among others. Once it identifies cookies associated with these platforms, the software attempts to grab the user’s accounts on them.

The captured data ranges from profile details to email addresses and user statuses. The stealer neatly organizes this stolen data and saves it in temporary text files within a uniquely generated folder. Before sending this data to attackers, the software crafts an embedded message that looks like a detailed report. This report, filled with developer specifics, user session information, and more, is then zipped and sent to the attackers via Discord.

Once dispatched, the stealer ensures all traces, including the temporary files and folders, are deleted.

In addition to stealing data from a device, Exela searches specific folders on a user’s computer to find and extract Discord tokens, a digital ID. These tokens can be decrypted to access more personal information from a user’s Discord profile. Beyond this, it can take screenshots of a user’s monitor and gather other system information like active window titles and saved Wi-Fi passwords.

Protecting Your System From Info-Stealing Malware

In May, Trend Micro researchers discovered a similar info-stealer targeting Discord and GitHub users. It could also swipe data from browsers and steal crypto wallet keys.

“The rise of open-source data stealers has been noteworthy in recent times due to their ability to adapt to specific requirements. These versatile tools serve as valuable assets for reconnaissance purposes, empowering TAs with the ability to collect critical information that could potentially fuel a range of malicious activities,” Cyble said.

Cyble recommends only downloading and installing software from reputable sources. The researchers warned against “acquiring software from online sources that lack credibility or proper verification.”

We also recommend using an antivirus to spot potentially malicious programs on your device. We’ve conducted extensive tests on antivirus solutions, and Norton 360 is currently our top pick.

You can learn how different antivirus programs performed in our tests and discover alternatives to Norton 360 in our article about the best antivirus.

For more privacy insights, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment