Celestial Stealer Malware: Advanced JavaScript Threat Via Telegram Network

In the ever-evolving landscape of online threats, Celestial Stealer stands out as a particularly sophisticated JavaScript-based infostealer targeting Chromium and Gecko-based browsers. This malevolent tool is explicitly designed to extract a wide array of sensitive information, including browsing history, saved passwords, autofill data, cookies, and even credit card details. By also keeping track of user-visited URLs and their frequencies, Celestial Stealer has the potential to exploit virtually every piece of data that passes through a user’s browser. What makes this malware even more alarming is its distribution model: operating as malware-as-a-service (MaaS) via Telegram. Individuals and groups can purchase memberships to access Celestial Stealer’s capabilities, which extend beyond browsers to inject payloads into applications such as Steam, Telegram, and cryptocurrency wallets like Atomic and Exodus.

The Infection Chain

Celestial Stealer’s infection process begins with an innocuous-looking Base64-encoded script masquerading as a Discord promotion generator tool. Once the script is activated, it is decrypted and executed through the certutil tool, a step that paves the way for the stealer to be retrieved from the command-and-control (C2) server. Once downloaded, the malware takes steps to obfuscate its presence and avoid detection by conventional security measures. Obfuscation techniques and anti-analysis tactics keep the stealer hidden while it goes to work on extracting sensitive data.

Researchers have noted that the malware even deploys regular updates to maintain its undetectable status. In one especially well-documented case, the stealer was disguised as a VR Chat ERP setup file, duping users into installing the malicious software under the guise of a seemingly legitimate application. This level of deception underscores the ne

Explore more

Prioritizing Mental Health in Remote and Hybrid Workspaces

The shift to remote and hybrid work models has fundamentally transformed the modern workplace, offering unprecedented flexibility and accessibility for employees across various industries, while also introducing new challenges to mental well-being. With the reduction of commuting stress and the ability to tailor work environments to personal needs, these setups have gained immense popularity among workers, including those with disabilities

Building an AI Work Culture That Embraces Honest Learning

What happens when a workforce feels compelled to bluff its way through the complexities of artificial intelligence? In today’s fast-paced corporate landscape, countless professionals nod confidently in meetings, toss around AI buzzwords, and keep tools like ChatGPT open on their screens, all to mask a startling truth: many lack the deep understanding they project. This silent charade, driven by fear

How Can Leaders Support Grieving Employees Effectively?

Imagine a workplace where an employee, grappling with the sudden loss of a loved one, returns to their desk only to face mounting deadlines and unspoken expectations, while the weight of grief clouds their focus, leaving no clear path to seek support or understanding. This scenario is far too common, as many organizations overlook the profound impact of loss on

How Can You Reignite Employee Engagement After Summer?

As summer fades into fall, a palpable shift occurs in workplaces across the Northern Hemisphere, where calendars once dotted with out-of-office replies now brim with meetings, deadlines loom larger, and the pressure to meet year-end targets intensifies. Yet, amid this transition, a troubling undercurrent persists: employee engagement often takes a nosedive. Why does this seasonal pivot feel like such a

Automated Hiring Tools: Alienating Top Talent?

What happens when the very tools designed to uncover top talent end up alienating the most promising candidates? In a job market where a single position can attract thousands of applicants, employers increasingly turn to automated hiring assessments to manage the deluge, yet beneath the promise of efficiency lies a troubling reality. These systems are reshaping how job seekers approach