-
123 Stealer
A new stealer has popped up. Below is a copy-paste of the thread from the XSS forum. Machine translated with some minor edits by me. Stealer, collects browser data, cookies, passwords, file grabber, process grabber, Chrome browser extensions, crypto wallet collection, well basically default stuff like every other stealer collects. You will need your own…
-
All things infostealers. Week 24, 2025
A brief look at all things infostealers for the week 24, 2025 (09.06.2025–15.06.2025). This week observed updates in MonsterV2 and Bee Stealer stealers, and emergence of Fusion Stealer. Grabbed some numbers from marketplaces and some interesting news/articles. Infostealer Updates MonsterV2 Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in…
-
Bee Stealer
I know, I did a boo-boo. I saw the posting of Bee Stealer (BeeStealer) on the XSS forum in the first half of May, but somehow it didn’t register in the back-end (brain), and therefore missed to include it earlier. Better late than never. Below is a copy-paste of the thread from the XSS forum.…
-
All things infostealers. Week 13, 2025
A brief look at all things infostealers for the week 13, 2025 (24.03.2025–30.03.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers. Infostealer Updates LummaC2 Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with…
-
StealC V2 – A Major Update to a Popular Infostealer
In the beginning of March 2025, user of XSS forum “plymouth” made a post in their stealer thread about the upcoming major update to the infostealer. Finally, on 30th March they posted announcement and details of the StealC V2 release. According to the user, the development of the second version took half a year, and…
-
mac.c macOS Stealer
On 14 March 2025, a user “mentalpositive” on XSS Forum has posted a thread advertising a new MacOS infostealer. Below is the machine translation of the user’s forum post, with minor edits by me. Screenshot from XSS Forum. User advertises the new infostealer mac.c macOS Stealer is a stealer for devices running the macOS operating…
-
Nightly claims to have access to Commercial Bank of Qatar
A user on a Russian-speaking forum XSS claims to have access to database of Commercial Bank of Qatar. User of the forum, who goes by name of nightly, has made a thread with minimal information about the access and hasn’t shared any (sample/full) data yet. However, given the past behaviour of the user, we can…
-
Okta Source Code Leak
A user on XSS forum, named nightly, has started a thread “Okta Source Code”, where they have shared some screenshots which allegedly depict their access. Might update this post if have time to analyse or get more info. Screenshot from XSS forum Below are screenshots shared by the user on the XSS forum:
-
All things infostealers. Week 43, 2024
A brief look at all things infostealers for the week 43, 2024 (21.10.2024–27.10.2024). My-my, during week 43 were observed a number of updates to several infostealers. As usual, added few articles and news pieces that were interesting. Specially the “Braodo Stealer” one, haven’t heard about such stealer before. XFiles Update Note: The update posts are…
-
All things infostealers. Week 41, 2024
A brief look at all things infostealers for the week 41, 2024 (07.10.2024–13.10.2024). Includes an update on XFiles, Lumma, StealC and Vidar stealers. And a news article on Ukrainian national pleading guilty to his involvement in the Raccoon Stealer. XFiles Update Note: The update post is copy-pasted as is from the XSS forum Update 3.11.0 08.10.2024**A…