{
  "family": "esfury",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nEsfury is a targeted Information Stealer (Info-Stealer) primarily focused on extracting FTP credentials, email logins, and stored web browser passwords from compromised Windows systems. Unlike highly sophisticated banking trojans that inject code into web browsers, Esfury operates as a quieter, \"smash-and-grab\" utility favored by cybercriminals for rapid credential harvesting and subsequent server compromise.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nEsfury is typically distributed via malicious email attachments (often masquerading as invoices or shipping documents) or bundled within cracked software available on torrent networks.\n\nUpon execution, Esfury initiates a rapid, localized search for high-value credentials:\n<ul>\n<li><strong>FTP/Webmaster Targeting:</strong> Esfury specifically hunts for configuration files and saved passwords associated with popular FTP clients (like FileZilla, CuteFTP, or WinSCP). Stolen FTP credentials allow the attacker to deface websites, inject malicious code into legitimate web pages, or host further malware payloads.</li>\n<li><strong>Browser and Email Harvesting:</strong> The malware scans the registry and local AppData folders to extract saved passwords from major web browsers (Chrome, Firefox, Internet Explorer) and email clients (Outlook, Thunderbird).</li>\n<li><strong>Data Exfiltration:</strong> Once the data is harvested, Esfury typically encrypts the stolen information and transmits it to an attacker-controlled server, often utilizing a hardcoded SMTP server to email the stolen data directly to the threat actor.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nAn Esfury infection poses a severe risk to an organization's external infrastructure. While the malware infects a local endpoint, the theft of FTP and webmaster credentials often leads directly to the compromise of the organization's public-facing websites or web applications, resulting in significant reputational damage and potential regulatory fines.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Infrastructure Credential Reset:</strong> If Esfury is detected, all passwords for internal and external FTP servers, web hosting control panels (cPanel/Plesk), and content management systems (WordPress) must be immediately rotated.</li>\n<li><strong>Local Password Reset:</strong> All user credentials saved in the affected endpoint's web browsers and email clients must be considered compromised and reset.</li>\n<li><strong>Endpoint Eradication:</strong> The malware itself is typically not heavily obfuscated and can often be removed by a reputable EDR or enterprise antivirus solution. Ensure a full system scan is completed to verify eradication.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan.PWS.Esfury",
    "Spyware.Esfury",
    "Win32/Esfury"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1555.003",
    "T1555.004",
    "T1056.001",
    "T1048"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T06:44:44Z",
  "type": "Information Stealer",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}