Cybercriminals are using Vega Stealer malware to target saved credentials and credit cards stored in Google Chrome and Firefox browsers and steal sensitive documents from infected computers, according to cybersecurity services provider Proofpoint.Proofpoint observed and blocked a low-volume Vega Stealer email campaign last week. The campaign targeted companies in the following sectors:Vega Stealer email campaign messages contained malicious attachments, Proofpoint indicated. Each message included a macro that downloaded a Vega Stealer payload.During a Vega Stealer attack, a macro retrieves a payload that is saved to a victim's computer in his or her "Music" directory, Proofpoint noted. After the Vega Stealer file is downloaded and saved, it is executed automatically on a victim's computer.Furthermore, Vega Stealer enables cybercriminals to access Firefox files used to store various passwords and keys, Proofpoint said.Vega Stealer represents flexible malware, according to Proofpoint. Going forward, Vega Stealer has the potential to evolve into a commonly used malware.
- Advertising.
- Manufacturing.
- Marketing.
- Public relations.
- Retail.
How Does Vega Stealer Impact Victims?
With Vega Stealer, cybercriminals can gather and exfiltrate a Chrome user's saved data, such as:- Cookies.
- Passwords.
- Profiles.
- Saved credit cards.
