Last seven days
- First activity
- Sep 17, 2026
- Last activity
- Sep 24, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 1 hostnames
RisePro is a Windows information-stealing malware family first observed in 2022 and commonly tracked as an infostealer offered and operated in cybercriminal ecosystems.
Profile source: Mallory opens in a new tabRisePro
RisePro is a Windows information-stealing malware family first observed in 2022 and commonly tracked as an infostealer offered and operated in cybercriminal ecosystems. It is designed to collect credentials, browser cookies, saved payment-card data, cryptocurrency wallet data, screenshots, host fingerprinting information, and selected files from infected systems. Targeted applications include major Chromium- and Gecko-based browsers, browser extensions associated with cryptocurrency wallets and two-factor authentication, and desktop applications such as Discord, battle.net, and Authy Desktop. RisePro also searches for wallet artifacts associated with multiple cryptocurrency clients and can package stolen data into archives for exfiltration.
The malware uses string and API obfuscation, dynamic import resolution, and in some cases embedded or remotely fetched legitimate DLLs to access browser data. It stages collected information in a temporary working directory, compresses the results, and communicates with command-and-control infrastructure over obfuscated HTTP using JSON-like messages protected with byte-substitution and XOR-based encoding. Reported command functionality includes retrieval of settings, grabber rules, and libraries, and available configuration indicates support for features such as screenshot capture, wallet theft, and collection of network-history data. Some analysis has suggested a possible loader capability, although that functionality has not been consistently observed in execution.
RisePro has been repeatedly associated with PrivateLoader-delivered infections, and multiple analyses have noted code, protocol, and infrastructure similarities between the two malware families, while stopping short of confirming a definitive development relationship. It has also appeared in multi-payload crimeware chains alongside other stealers and commodity malware. In observed Windows intrusions, RisePro established persistence through scheduled tasks and startup shortcuts, sometimes configured to run at logon and with elevated privileges.
Distribution has been linked to cracked-software lures, including fake installers and repositories masquerading as pirated software projects, as well as broader malware delivery ecosystems that use loaders to inject RisePro into legitimate Windows processes. RisePro has also been cited among infostealers whose stolen credentials were later abused in follow-on compromises, including access to enterprise services. The malware is widely recognized in the stealer landscape for theft of passwords, payment data, and cryptocurrency-related information from Windows endpoints.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 351dc84d3ce09953cb240b9674cf19b5e51557e1153e24c0e0424f095d89fd67 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 d1a9af107653b79fa2c10cc852c3ed6c4f37574277ccbc2bec97c1eaf3565cd0 2a018987d8fb348a3e5e05595afbcd4bfa5631b6e0df83219390cca2e5ea758a bed76b617a0dd97871dccc90d1b52c1760be066aabda67990308b22c29877a16 44593e8065a0f6c19d3a8fe2c49f13d1d202c2f78cf8a6157e01ca6d15164298 68130e5ff74c361cf84743a48d9da067b126a90f09d11cf64a322b1dfe2c9900 a2fa794887ecb96a4b40389fe152e52707c021c86f63c4430557e7c286840b96 c645d7f9a1588e028ad93a649ba5e95fc22a97e9ef7ea52fb3123ea7cac32469 MITRE ATT&CK
Reporting
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.