Celestial Stealer Malware: Advanced JavaScript Threat Via Telegram Network

In the ever-evolving landscape of online threats, Celestial Stealer stands out as a particularly sophisticated JavaScript-based infostealer targeting Chromium and Gecko-based browsers. This malevolent tool is explicitly designed to extract a wide array of sensitive information, including browsing history, saved passwords, autofill data, cookies, and even credit card details. By also keeping track of user-visited URLs and their frequencies, Celestial Stealer has the potential to exploit virtually every piece of data that passes through a user’s browser. What makes this malware even more alarming is its distribution model: operating as malware-as-a-service (MaaS) via Telegram. Individuals and groups can purchase memberships to access Celestial Stealer’s capabilities, which extend beyond browsers to inject payloads into applications such as Steam, Telegram, and cryptocurrency wallets like Atomic and Exodus.

The Infection Chain

Celestial Stealer’s infection process begins with an innocuous-looking Base64-encoded script masquerading as a Discord promotion generator tool. Once the script is activated, it is decrypted and executed through the certutil tool, a step that paves the way for the stealer to be retrieved from the command-and-control (C2) server. Once downloaded, the malware takes steps to obfuscate its presence and avoid detection by conventional security measures. Obfuscation techniques and anti-analysis tactics keep the stealer hidden while it goes to work on extracting sensitive data.

Researchers have noted that the malware even deploys regular updates to maintain its undetectable status. In one especially well-documented case, the stealer was disguised as a VR Chat ERP setup file, duping users into installing the malicious software under the guise of a seemingly legitimate application. This level of deception underscores the ne

Explore more

Trend Analysis: Iranian Cyber Espionage Tactics

A Rising Threat in the Digital Shadows Imagine a seemingly innocuous LinkedIn message from a recruiter offering a dream job at a reputable telecommunications firm, only to discover later that it was a meticulously crafted lure to infiltrate critical systems. This scenario unfolded in a recent campaign by UNC1549, an Iran-linked threat actor also known as Subtle Snail, which compromised

How Did Harrods’ Supply Chain Breach Affect Customers?

Imagine a luxury retailer, synonymous with prestige and trust, suddenly grappling with a data breach that exposes the personal information of nearly half a million customers. This scenario became reality for Harrods, the iconic London department store, when a vulnerability in a third-party provider’s system led to the leak of up to 430,000 customer records. While payment details remained secure,

Agentic AI Security Platform – Review

Imagine a world where artificial intelligence drives critical business operations, from financial transactions to regulatory compliance, yet remains a prime target for sophisticated cyberattacks that traditional security tools can’t counter. This is the reality for enterprises today, as the rapid adoption of AI introduces unique vulnerabilities like prompt injection attacks that can manipulate autonomous systems. CrowdStrike, a leader in cybersecurity,

Salesforce Security Threats – Review

Setting the Stage for Salesforce Security Challenges In an era where cloud-based platforms underpin critical business operations, Salesforce stands as a cornerstone for customer relationship management across countless industries. However, with its widespread adoption comes a stark reality: a single breach can expose sensitive data, disrupt operations, and erode trust on a massive scale, making cybersecurity a top priority for

Trend Analysis: Stablecoin Payroll for Fintech Startups

In an era where digital currencies are reshaping the very fabric of financial transactions, fintech startups across Asia are at the forefront of a groundbreaking shift by adopting stablecoin payroll systems to revolutionize how they compensate their workforce. Imagine a world where salary payments are instantaneous, unaffected by currency fluctuations, and free from exorbitant cross-border fees—this is no longer a