Security Startup Finds Flaw to Lock Out Mars Stealer Malware Operators

Researchers discover a vulnerability that lets them remotely disable Mars Stealer servers, delete stolen data, and cut ties with infected victims. The unorthodox countermeasure permanently locks cybercriminals out of their own malicious dashboards.

Security startup Buguard discovers a coding flaw in the Mars Stealer malware that allows it to remotely lock out cybercriminals from their own command and control servers. Mars Stealer is a popular data-stealing malware as a service that cybercriminals rent to steal passwords, two-factor codes, and cryptocurrency wallets from infected victims. The malware spreads through malicious email attachments, deceptive advertisements, and bundled files on torrenting sites.

The vulnerability originates from a cracked copy of Mars Stealer that leaks online earlier in the year. This leaked version contains flawed documentation that guides operators to configure their servers in a way that inadvertently exposes stolen log files and sometimes even infects the operators themselves. Buguard exploits this specific misconfiguration to break into the servers, delete the stolen logs, and terminate all active connections with victims' computers.

Once the flaw is exploited, the startup scrambles the dashboard's password so the malware operators cannot log back into their systems. This unorthodox practice, commonly known as "hacking back," is highly debated in the cybersecurity community but effectively forces the cybercriminals to lose all their stolen data and start their campaigns over from scratch.

Read More at the original source →