Skip to content
Malware family

Pentagon Stealer

Pentagon Stealer is a malware family identified in 2025 and described in the provided reporting as an Android banking malware variant.

Profile source: Mallory opens in a new tab

Pentagon Stealer

Family profile

Pentagon Stealer is a malware family identified in 2025 and described in the provided reporting as an Android banking malware variant. ANY.RUN reported it among notable threat discoveries in 2025 alongside Salvador Stealer, and separate reporting also listed it as one of three new information stealer malware families detected in the wild. It was first discovered in March 2025. The malware has a Golang-based implementation, and a Python variant of the same stealer had been observed at least a year earlier, distributed through fake Python packages uploaded to the PyPI repository. Based on the available content, high-confidence characteristics are that it is associated with Android targeting, banking-malware behavior, and stealer functionality, with observed propagation via malicious PyPI packages for the Python variant. No specific threat actor attribution, victim industry focus, or concrete indicators of compromise are provided in the content.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • NL1

Leading providers

  • Julian Achter1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.