Skip to content

RisePro

RisePro is a Windows information-stealing malware family first observed in 2022 and commonly tracked as an infostealer offered and operated in cybercriminal ecosystems.

Profile source: Mallory opens in a new tab

RisePro

Family profile

RisePro is a Windows information-stealing malware family first observed in 2022 and commonly tracked as an infostealer offered and operated in cybercriminal ecosystems. It is designed to collect credentials, browser cookies, saved payment-card data, cryptocurrency wallet data, screenshots, host fingerprinting information, and selected files from infected systems. Targeted applications include major Chromium- and Gecko-based browsers, browser extensions associated with cryptocurrency wallets and two-factor authentication, and desktop applications such as Discord, battle.net, and Authy Desktop. RisePro also searches for wallet artifacts associated with multiple cryptocurrency clients and can package stolen data into archives for exfiltration.

The malware uses string and API obfuscation, dynamic import resolution, and in some cases embedded or remotely fetched legitimate DLLs to access browser data. It stages collected information in a temporary working directory, compresses the results, and communicates with command-and-control infrastructure over obfuscated HTTP using JSON-like messages protected with byte-substitution and XOR-based encoding. Reported command functionality includes retrieval of settings, grabber rules, and libraries, and available configuration indicates support for features such as screenshot capture, wallet theft, and collection of network-history data. Some analysis has suggested a possible loader capability, although that functionality has not been consistently observed in execution.

RisePro has been repeatedly associated with PrivateLoader-delivered infections, and multiple analyses have noted code, protocol, and infrastructure similarities between the two malware families, while stopping short of confirming a definitive development relationship. It has also appeared in multi-payload crimeware chains alongside other stealers and commodity malware. In observed Windows intrusions, RisePro established persistence through scheduled tasks and startup shortcuts, sometimes configured to run at logon and with elevated privileges.

Distribution has been linked to cracked-software lures, including fake installers and repositories masquerading as pirated software projects, as well as broader malware delivery ecosystems that use loaders to inject RisePro into legitimate Windows processes. RisePro has also been cited among infostealers whose stolen credentials were later abused in follow-on compromises, including access to enterprise services. The malware is widely recognized in the stealer landscape for theft of passwords, payment data, and cryptocurrency-related information from Windows endpoints.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 24, 2026
Feed role
C2 / Distribution
Host form
8 IP / 1 hostnames

Leading locations

  • DE2
  • NL2
  • RU2
  • CN1
  • GR1
  • US1

Leading providers

  • FEMO IT SOLUTIONS LIMITED2
  • Omegatech LTD2
  • Contabo Inc.1
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • HOSTMEIN IKE1
  • PJSC Rostelecom1

Infrastructure traits

  • Hosting 8

Samples

Recent associated samples

MITRE ATT&CK

RisePro in ATT&CK

39 distinct techniques

Reporting

Research mentioning RisePro

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

Aug 5
The Record Media

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | The Record from Recorded Future News

Aug 5
Darkwebinformer

Canadian Hacker Pleads Guilty in Cloud Breach Spree Affecting More Than 165 Organizations

Aug 5
Us Department Of Justice

Office of Public Affairs | Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions | United States Department of Justice

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.