Skip to content

RisePro

RisePro is a Windows infostealer first observed in 2022 that is used to harvest sensitive data from infected systems, including saved credentials, browser data, payment card information, and cryptocurrency wallet data.

Profile source: Mallory opens in a new tab

RisePro

Family profile

RisePro is a Windows infostealer first observed in 2022 that is used to harvest sensitive data from infected systems, including saved credentials, browser data, payment card information, and cryptocurrency wallet data. It is part of the commodity stealer ecosystem frequently discussed alongside families such as RedLine, Vidar, Lumma, and StealC, and has been implicated in credential exposure that later enabled follow-on intrusions against enterprise services.

RisePro has been distributed through multiple criminal delivery channels. Documented infection chains include cracked-software lures, malicious GitHub repositories, Discord-amplified malware distribution, and pay-per-install loader ecosystems such as PrivateLoader. In observed campaigns, loader components have injected RisePro into legitimate Windows processes to reduce detection and have delivered it alongside other malware families in multi-payload monetization chains.

On infected hosts, RisePro steals credentials and other browser-resident data and exfiltrates the collected information to operator-controlled infrastructure. It has been associated with theft of passwords, credit card data, and cryptocurrency wallet information. In some observed infections it also established persistence through scheduled tasks and startup shortcuts. Reporting also places RisePro among the infostealers whose stolen logs are traded in criminal marketplaces and later abused for credential stuffing, account takeover, and access brokerage.

RisePro has appeared in broader intrusion ecosystems affecting both consumer and corporate machines. It has been cited among the infostealers linked to exposed credentials used in Snowflake-related compromises and has also been associated with campaigns targeting users in Latin America through phishing-adjacent delivery chains and with malware hosted on GitHub and Discord infrastructure. Overall, RisePro is best understood as a commodity infostealer focused on credential and financial-data theft, commonly delivered through social-engineering-driven malware distribution and often used as an upstream enabler for subsequent criminal operations.

Capabilities

  • Credential Theft
  • Exfiltration
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 10, 2026
Feed role
C2 / Distribution
Host form
19 IP / 6 hostnames

Leading locations

  • RU5
  • CN4
  • US4
  • DE2
  • NL2
  • AT1
  • BR1
  • CA1
  • GR1
  • HK1
  • IE1
  • LU1

Leading providers

  • CHINA UNICOM China169 Backbone2
  • New Hosting Technologies LLC2
  • Omegatech LTD2
  • AEZA GROUP LLC1
  • Amazon.com, Inc.1
  • cognetcloud INC1

Infrastructure traits

  • Hosting 21

Samples

Recent associated samples

MITRE ATT&CK

RisePro in ATT&CK

11 distinct techniques

Reporting

Research mentioning RisePro

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driverโ€™s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflakeโ€™s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.