Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The first layer of the Packer makes use of junk code and useless loops to avoid analysis and prevent detonation in automated analysis systems.
The malware will resolve its API calls dynamically using hashes.
After exfiltration, it uses DeleteUrlCacheEntry with the C2 as a parameter for the API call, which deletes the cache entry for a given URL.
The Shellcode is decrypted using a 32 byte key in blocks of 8 bytes.
RedLine stealer... Collecting credentials, cookies, credit cards from Chromium- and Gecko-based browsers
One curious difference from earlier Taurus Stealer versions is that the Active Window from the infected machine is now also included in the information gathering process.
This grabber is used in the Outlook Stealing functionality and uses advapi32.dll RegOpenKeyA, RegEnumKeyA, RegQueryValueExA and RegCloseKey API calls to access the and steal from Windows Registry.
An example of the response from the C2 could be ... #[156.146.57.112;US]#[] ... It gets information ... IP: ... Country:
Current username: User ... Computername: USER-PC ... Domain: WORKGROUP ... Computer users: All Users, Default, Default User, Public, User
It gets information and concatenates it sequentially in memory until we get the final result: ... OS: Windows 6.1 7601 x64 ... CPU name ... GPU name ... RAM ... Screen resolution ...
This is one of the most used grabbing methods... and consists of traversing files (it ignores directories) by using kernel32.dll FindFirstFileA, FindNextFileA and FindClose API calls.
After resolving these API calls, it enters in a function that will prevent the malware from detonating if it is being executed in an emulated environment.
Taurus Stealer uses wininet APIs InternetOpenA, InternetSetOptionA, InternetConnectA, HttpOpenRequestA, HttpSendRequestA, InternetReadFile and InternetCloseHandle for its networking functionalities.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer previously delivered by a similar AutoIt-based campaign to steal credentials, cookies, browsing history, system information, and more.
Known information stealer whose code was adopted as a core component in the campaign discussed under the new actor case.
An infostealer referenced as the parent/fork source for GlorySprout. The content notes Taurus Stealer has been previously dissected and can be used as a comparison point when analyzing GlorySprout capabilities.
C/C++ information-stealing malware that steals browser data, credentials, cookies, wallet files, Outlook data, Windows Vault contents, and system information; communicates with a C2 using RC4+Base64-protected traffic; supports optional anti-VM, loader, self-delete, and dynamic grabber capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.