Home Malware Programs Trojans Evrial Trojan

Evrial Trojan

Posted: January 23, 2018

Threat Metric

Ranking: 2,339
Threat Level: 2/10
Infected PCs: 525
First Seen: August 16, 2023
Last Seen: October 16, 2023
OS(es) Affected: Windows

The Evrial Trojan is a harmful application developed by Russian cybercrooks, which appear to sell it on underground hacking forums that are popular in the Russia region. This threat is capable of collecting login credentials from various Web browsers, but the feature that stands out the most is its ability to detect when certain strings are copied to the clipboard, and then replace them with strings specified by the attackers. It appears that this feature is being used to replace various wallet addresses related to cryptocurrencies silently, as well as replace Steam trade links with the ones that belong to the account of the attacker. This might mislead many victims into sending their money to the anonymous attacker instead of the original receiver unknowingly.

One of the most concerning things about the Evrial Trojan is its price – with a price tag of just $25, anyone can get access to the building kit, which can be used to create a fully weaponized and personalized version of the Trojan. The Evrial Trojan is capable of exfiltrating login credentials and other data from popular Web browsers like Chrome and Opera. However, it is also compatible with less popular Web browsing clients such as Torch, Comodo, Yandex, and others. The clipboard hijacking feature is able to detect addresses linked to Bitcoin, Litecoin, Monero, WebMoney, Qiwi, and then replace them with the corresponding address set by the attacker.

Another interesting ability that the Evrial Trojan possesses is to collect cookies from the computer, as well as various document files if they are on the desktop. In addition to this, the Evrial Trojan can take screenshots, which will then be uploaded to the attacker's FTP server, therefore allowing them to receive even more information about their victims.

Since the Evrial Trojan is programmed to work in stealth mode, it might be impossible for the average user to notice this threat's presence. The best way to ensure that your information and details are safe is to guarantee that your PC is protected 24/7 by a reputable anti-virus software suite.

Technical Details

Additional Information

The following URL's were detected:
datlngllfe.net
Loading...