What does Erbium InfoStealer do?

Identity Theft Passwords

Erbium is a newly discovered infostealing malware. The malicious tool was put up for sale on the dark web by a Russian-speaking threat actor back in the summer of 2022.

Erbium is sold for a relatively modest price, with subscriptions ranging from a mere $10 for a week to $150 for a full year. Prices took a hike up in August and a single month started selling for $100. While initially offered through a web page, the malware switched to a Telegram bot that handles its customers and subscriptions.

The malware has an obfuscated executable and features polymorphic capabilities that make detection harder. The malware uses a legitimate Windows application to deploy itself.

Once deployed in memory, the malware contacts its command and control server and downloads a malicious DLL, which comprises the final payload.

Erbium can capture screenshots from the infected system, scrape system information, search for and steal form-fill data saved in browsers, as well as scrape a number of cold wallets for a great number of cryptocurrencies.

The malware targeted victims located in the US, Europe and India.

October 4, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.