Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 24, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 3 hostnames
Stealerium is an open-source .NET/C# information stealer first noted in 2022 and publicly available on GitHub, where it was described as a stealer, clipper, and keylogger.
Profile source: Mallory opens in a new tabStealerium
Stealerium is an open-source .NET/C# information stealer first noted in 2022 and publicly available on GitHub, where it was described as a stealer, clipper, and keylogger. It is widely referenced as an infostealer family and as the codebase underlying later forks and variants, including Phantom Stealer/PhantomStealer, with multiple reports noting significant code overlap and family lineage.
High-confidence capabilities described in the source material include theft of browser credentials, browser cookies, session tokens, cryptocurrency wallet data, and general sensitive information from compromised Windows systems. Stealerium can exfiltrate stolen data through multiple channels, especially Discord webhooks, and reporting also associates the broader family with SMTP, Telegram, FTP, and other exfiltration paths in derived variants. The malware also includes clipper functionality to replace copied cryptocurrency wallet addresses and keylogging functionality.
A notable feature documented by Proofpoint is NSFW-triggered surveillance behavior: Stealerium can be configured to monitor open browser tabs for keywords such as "sex" or "porn" and, when triggered, capture a desktop screenshot and a webcam image. Reporting states newer modules were added specifically to support sextortion-style abuse and blackmail.
Stealerium has been delivered in phishing and social-engineering campaigns, including ClickFix-style chains and campaigns using malicious SVG files to trigger PowerShell execution. It has also appeared in multilingual phishing activity, including Italian-language campaigns. The malware has been observed or reported in campaigns targeting enterprise victims and sectors including logistics, industrial, manufacturing, technology, retail, construction, and IT, though some of those campaigns involved Stealerium-derived Phantom variants rather than base Stealerium itself.
The content also notes operational abuse of Discord infrastructure: Stealerium has used Discord webhooks to steal credentials, browser cookies, and cryptocurrency wallets, and broader reporting cited it among malware families abusing Discord services for delivery or exfiltration.
Relevant high-confidence indicators and associations mentioned in the content include the GitHub handle "witchfindertr" as the public developer identity for the released codebase, Discord webhook-based exfiltration, and strong code/family overlap with Phantom Stealer/PhantomStealer. The content does not provide a canonical malware hash for base Stealerium itself.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 716d698765e5bc3f936f7d28edc5b47839dfe8568a1311a57d2f8dbf73654b7c 2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac c42130f2f9f1fc1a1c4189b6cc3bc5ce0207d21620e20cc4119ae86951105344 c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 Reported operators
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
... delivering an open-source information stealer called Stealerium (or variants of it).
... delivering an open-source information stealer called Stealerium (or variants of it).
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.