Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 14 IP / 9 hostnames
RisePro is a Windows infostealer first observed in 2022 that is used to harvest sensitive data from infected systems, including saved credentials, browser data, payment card information, and cryptocurrency wallet data.
Profile source: Mallory opens in a new tabRisePro
RisePro is a Windows infostealer first observed in 2022 that is used to harvest sensitive data from infected systems, including saved credentials, browser data, payment card information, and cryptocurrency wallet data. It is part of the commodity stealer ecosystem frequently discussed alongside families such as RedLine, Vidar, Lumma, and StealC, and has been implicated in credential exposure that later enabled follow-on intrusions against enterprise services.
RisePro has been distributed through multiple criminal delivery channels. Documented infection chains include cracked-software lures, malicious GitHub repositories, Discord-amplified malware distribution, and pay-per-install loader ecosystems such as PrivateLoader. In observed campaigns, loader components have injected RisePro into legitimate Windows processes to reduce detection and have delivered it alongside other malware families in multi-payload monetization chains.
On infected hosts, RisePro steals credentials and other browser-resident data and exfiltrates the collected information to operator-controlled infrastructure. It has been associated with theft of passwords, credit card data, and cryptocurrency wallet information. In some observed infections it also established persistence through scheduled tasks and startup shortcuts. Reporting also places RisePro among the infostealers whose stolen logs are traded in criminal marketplaces and later abused for credential stuffing, account takeover, and access brokerage.
RisePro has appeared in broader intrusion ecosystems affecting both consumer and corporate machines. It has been cited among the infostealers linked to exposed credentials used in Snowflake-related compromises and has also been associated with campaigns targeting users in Latin America through phishing-adjacent delivery chains and with malware hosted on GitHub and Discord infrastructure. Overall, RisePro is best understood as a commodity infostealer focused on credential and financial-data theft, commonly delivered through social-engineering-driven malware distribution and often used as an upstream enabler for subsequent criminal operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 c2214a8b8c88c91a009891f3f10bbb2d8aa18a15580bd12c82dfcf2477f0c846 c26e2475ef60ba969bb66c9b464b498efb1da0bf7360ff7545c1db3b707bdbed 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 16930620b3b9166e0ffbd98f5d5b580c9919fd6ccdcc74fb996f53577f508267 MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driverโs license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflakeโs SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.