Skip to content
Malware family

Stealerium

Stealerium is an open-source .NET/C# information stealer first noted in 2022 and publicly available on GitHub, where it was described as a stealer, clipper, and keylogger.

Profile source: Mallory opens in a new tab

Stealerium

Family profile

Stealerium is an open-source .NET/C# information stealer first noted in 2022 and publicly available on GitHub, where it was described as a stealer, clipper, and keylogger. It is widely referenced as an infostealer family and as the codebase underlying later forks and variants, including Phantom Stealer/PhantomStealer, with multiple reports noting significant code overlap and family lineage.

High-confidence capabilities described in the source material include theft of browser credentials, browser cookies, session tokens, cryptocurrency wallet data, and general sensitive information from compromised Windows systems. Stealerium can exfiltrate stolen data through multiple channels, especially Discord webhooks, and reporting also associates the broader family with SMTP, Telegram, FTP, and other exfiltration paths in derived variants. The malware also includes clipper functionality to replace copied cryptocurrency wallet addresses and keylogging functionality.

A notable feature documented by Proofpoint is NSFW-triggered surveillance behavior: Stealerium can be configured to monitor open browser tabs for keywords such as "sex" or "porn" and, when triggered, capture a desktop screenshot and a webcam image. Reporting states newer modules were added specifically to support sextortion-style abuse and blackmail.

Stealerium has been delivered in phishing and social-engineering campaigns, including ClickFix-style chains and campaigns using malicious SVG files to trigger PowerShell execution. It has also appeared in multilingual phishing activity, including Italian-language campaigns. The malware has been observed or reported in campaigns targeting enterprise victims and sectors including logistics, industrial, manufacturing, technology, retail, construction, and IT, though some of those campaigns involved Stealerium-derived Phantom variants rather than base Stealerium itself.

The content also notes operational abuse of Discord infrastructure: Stealerium has used Discord webhooks to steal credentials, browser cookies, and cryptocurrency wallets, and broader reporting cited it among malware families abusing Discord services for delivery or exfiltration.

Relevant high-confidence indicators and associations mentioned in the content include the GitHub handle "witchfindertr" as the public developer identity for the released codebase, Discord webhook-based exfiltration, and strong code/family overlap with Phantom Stealer/PhantomStealer. The content does not provide a canonical malware hash for base Stealerium itself.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 24, 2026
Feed role
C2 / Distribution
Host form
6 IP / 3 hostnames

Leading locations

  • NL2
  • US2
  • CN1
  • DE1
  • FR1
  • RU1
  • SG1

Leading providers

  • Beijing Qihu Technology Company Limited1
  • Cloudflare, Inc.1
  • DDOS-GUARD LTD1
  • FEMO IT SOLUTIONS LIMITED1
  • GTHost1
  • Hubei Feixun Network Co., Ltd1

Infrastructure traits

  • Hosting 9
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

TA2536

... delivering an open-source information stealer called Stealerium (or variants of it).

TA2715

... delivering an open-source information stealer called Stealerium (or variants of it).

MITRE ATT&CK

Stealerium in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.