Sys01

Malware updated 6 months ago (2024-11-29T13:55:08.177Z)
Download STIX
Preview STIX
SYS01, also known as Album Stealer and S1deload Stealer, is a harmful malware that has been in existence since 2022. The malware, which started as a C# stealer, has evolved into a PHP stealer, making it more potent and effective in its malicious activities. It's spread through Meta's advertising platform as part of an increasingly prominent campaign. In a novel approach, the SYS01 malware is now delivered through an ElectronJs application, broadening its reach and making it more difficult to detect and counteract. The distribution tactics of the SYS01 Infostealer campaign are highly sophisticated, typically utilizing ads that point to a MediaFire link or similar, enabling direct download of the malware. Indicators of Compromise (IoCs) have been identified across numerous domains, including krouki.com, kimiclass.com, goodsuccessmedia.com, among others. Command-and-Control (C2) Domains like musament.top, enorgutic.top, untratem.top, and several others are also linked to the SYS01 campaign. The adaptability of the cybercriminals behind these attacks makes the SYS01 Infostealer campaign especially dangerous. Analysis of a memory dump of the php.exe index.php process reveals the presence of the 'SYS01' string multiple times, indicating the malware's activity. The malware can use a plethora of C2 domains, and even more can be obtained via Telegram bots or Google pages. Moreover, the process employs SQL commands with potentially malicious intentions, such as 'SELECT * FROM moz_cookies', further emphasizing the threat posed by this malware.
Description last updated: 2024-10-31T12:01:56.372Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Sys01 Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more