Skip to content

Phemedrone Stealer

Phemedrone Stealer is a Windows-focused .NET information stealer written in C# and widely associated with credential and data theft from consumer applications and browsers.

Profile source: Mallory opens in a new tab

Phemedrone Stealer

Family profile

Phemedrone Stealer is a Windows-focused .NET information stealer written in C# and widely associated with credential and data theft from consumer applications and browsers. It has been described as open source and has been promoted in criminal ecosystems, while also appearing in active intrusion chains operated by multiple threat actors. The malware is designed to collect data in memory and steal information from Chromium- and Gecko-based browsers, cryptocurrency wallets, Discord, Telegram, FileZilla, Steam, screenshots, user files, and detailed host reconnaissance data. Reported theft includes passwords, cookies, browser-stored payment data, wallet material, messaging-session data, and other sensitive system information, followed by exfiltration to attacker-controlled infrastructure, including Telegram-based channels or bots.

Observed delivery chains show Phemedrone distributed through malicious Internet Shortcut files that exploit the Microsoft Windows Defender SmartScreen bypass vulnerability CVE-2023-36025. In documented campaigns, attackers used .url files to retrieve and execute Control Panel payloads, abuse signed Windows binaries, invoke PowerShell download stages, and fetch additional components from public hosting services before launching the final stealer. Other campaigns used social-engineering lures and multi-stage loaders, including encrypted PowerShell and .NET injector components, to hollow legitimate Windows processes and run Phemedrone under the guise of benign system activity. The malware has also been observed as an additional payload deployed by XWorm operators and as part of broader malware distribution ecosystems abusing platforms such as YouTube to push stealers through cracked-software and cheat-themed lures.

Phemedrone employs multiple defense-evasion and execution techniques in observed intrusions. These include SmartScreen bypass via CVE-2023-36025, obfuscated PowerShell stages, DLL sideloading, scheduled-task persistence, in-memory execution through Donut, API hashing, string encryption, packing and protector use, and process hollowing or injection through intermediary loaders. In one documented chain, a loader established persistence and repeatedly launched a sideloaded executable, which decrypted and executed a second-stage component before loading the final .NET stealer in memory. The malware has also been associated with anti-analysis claims such as anti-VM, anti-debug, and anti-CIS checks in criminal marketing.

Phemedrone primarily targets Windows users and is relevant to financially motivated cybercrime because of its focus on credentials, browser sessions, cryptocurrency assets, and messaging-platform data. It has been linked to exploitation activity by multiple criminal operators rather than a single exclusive actor, and code-level similarities have been noted between Phemedrone and other stealers such as Ov3r_Stealer. Its combination of commodity availability, active exploitation, and broad data-theft coverage makes it a notable infostealer in the current Windows threat landscape.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Process Injection
  • Reconnaissance
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 17, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Liu Kong

Trustwave said it identified a near-identical infection chain ... to drop another stealer called Phemedrone Stealer by exploiting the Microsoft Windows Defender SmartScreen bypass flaw (CVE-2023-36025).

Exploited software

Vulnerabilities linked to Phemedrone Stealer

1 CVEs

MITRE ATT&CK

Phemedrone Stealer in ATT&CK

33 distinct techniques

Reporting

Research mentioning Phemedrone Stealer

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.