OLDBAIT, also referred to as Sasfis in the provided content, is credential-stealing malware associated with the criminal group Smoky Spider, which is described as using SmokeLoader and Sasfis as loader and downloader malware respectively. The malware collects credentials from several email clients as well as from Internet Explorer, Mozilla Firefox, and Eudora. It can use HTTP and SMTP for command-and-control communications. The content also states that OLDBAIT installs itself at %ALLUSERPROFILE%\Application Data\Microsoft\MediaPlayer\updatewindws.exe, using a masquerading path and filename with subtle misspellings.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Attributed to the criminal group Smoky Spider, a group that uses SmokeLoader and Sasfis, loader and downloader respectively.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.
The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sasfis is mentioned as a downloader used by the Smoky Spider criminal group alongside SmokeLoader.
Malware that collects credentials from several email clients.
Malware that collects credentials from several email clients.
Malware that collects credentials from browsers and Eudora.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.