The temporary download folder unleashes 35% of infostealers on Windows

Executing files directly from the temporary download folder has emerged as the primary gateway for infostealers targeting Windows systems. A recent study conducted by Kaspersky Digital Footprint Intelligence reveals that this seemingly innocuous folder accounts for approximately 35% of the analyzed infections. Interestingly, this straightforward method outpaces more sophisticated techniques, highlighting a paradox in user behavior. The second most common entry point, C:WindowsMicrosoft.NETFramework, appears in 32% of cases and is associated with advanced tactics such as process injection.

The temporary folder accounted for one in three analyzed cases

The findings stem from the comprehensive report titled Malware Propagation Paths: An Analysis of Infostealer Locations on Infected File Systems, which Kaspersky compiled from five million records unearthed on the dark web over the past year. These records contained sensitive information harvested from compromised devices. The analysis identifies C:UsersAppDataLocalTemp as the leading route, with around 35% of the infostealers executed from this location. This trend underscores a recurring pattern where users open downloads directly from temporary folders without verifying their origins or relocating the files.

Fake installers compete with more advanced injection techniques

Following closely, the C:WindowsMicrosoft.NETFramework directory ranks as the second most frequent source, appearing in 32% of cases. This location is notorious for harboring more intricate techniques, including process injection, which facilitates the stealthy execution of malicious code. Many infections stem from everyday user choices, often linked to downloads from dubious sources, unauthorized program activations, and the temporary disabling of security measures. Malicious files frequently masquerade as legitimate software, including fake codecs, program activators, or game modifications. These deceptive files often present themselves as standard installations, gaining traction when users disable their antivirus software to complete the process.

Among the various families of malware analyzed, Vidar often disguises itself as Bootstrapper.exe, while RisePro employs names like MPGPH.exe or MSIUpdater.exe. Stealc utilizes a mix of descriptive and random names, such as LicenceVersionLoader.exe, to further obfuscate its true nature. Lumma, on the other hand, leverages generic naming conventions alongside .NET-based obfuscation techniques.

Kaspersky asks to monitor exposed assets on the internet and not disable antivirus

For organizations, Kaspersky recommends implementing digital risk protection services that monitor assets and detect threats across the internet surface, deep web, and dark web. This proactive approach aims to identify leaks and malicious activities before they escalate into significant operational disruptions. For individual users, the guidance is more straightforward yet equally critical. Kaspersky emphasizes the importance of downloading programs exclusively from official sources, utilizing password managers, keeping systems updated, and enabling multi-factor authentication. The company strongly advises against disabling antivirus software during installations, even when the file appears to be an activator or an update. This precaution is vital to safeguarding against the ever-evolving landscape of cyber threats.

Tech Optimizer
The temporary download folder unleashes 35% of infostealers on Windows