This newly-discovered malware targets Windows to steal sensitive data

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Fortinet has unveiled preliminary details of a ThirdEye, a new info-stealing malware awarded a medium severity level, meaning the risk posed to victims is potentially considerable.

The company’s FortiGuard Labs discovered the stealer when it came across suspicious-looking files in a cursory review. 

The good news is that the analysts believe it not to be sophisticated in nature, but even so, Fortinet suggests that the information stolen from victim machines could go on to be used for future attacks.

ThirdEye infostealer witnessed in the wild

Suspicions were raised when the team found a Russian file name in a file archive. The name, “Табель учета рабочего времени.zip,” translates to timesheet. Inside the zipped folder are two files that pose as documents, but are actually executables. 

The .exe files are designed to target Windows machines, which have long been the subject of attacks. However, recent months have seen many attackers shift their attention to Android devices, with multiple reports of malicious apps being hosted in the Play Store.

When successfully deployed, the malware steals information like BIOS and hardware data and sends it back to its C2 server.

While early versions of the malware, dating back to April, collected little more than client_hash, OS_type, host_name, and user_name, modifications a few weeks later added new parameters targeting CPU and RAM information, network interface data, and BIOS information. 

Fortinet believes that the malware serves the purpose of “understanding and narrowing down potential targets,” and that it might be looking to target Russian victims given the language used and the fact that it was found on a public scanning service from the country.

Currently, the analysts aren’t overly concerned with the malware’s sophistication, but evidence of developments suggest that future versions could be even more intrusive. 

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A white padlock on a dark digital background.
A new and dangerous keylogger is on the loose - here's how to stay safe
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring