Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 24 IP / 12 hostnames
Stealerium is an open-source .NET information stealer written in C# that emerged in 2022 and has been widely reused, modified, and operationalized in criminal campaigns.
Profile source: Mallory opens in a new tabStealerium
Stealerium is an open-source .NET information stealer written in C# that emerged in 2022 and has been widely reused, modified, and operationalized in criminal campaigns. It is best known as an infostealer with additional keylogging and cryptocurrency clipper functionality, and it has served as the codebase foundation for related malware such as Phantom Stealer and Enigma Stealer. Security reporting has repeatedly linked Stealerium-family malware to financially motivated activity, including phishing and ClickFix-style social-engineering campaigns, as well as broader commodity malware ecosystems targeting enterprise users and individuals.
Core Stealerium functionality includes theft of browser-stored credentials, cookies, session tokens, cryptocurrency wallet data, and other sensitive application data from compromised Windows systems. Reported variants and forks have also collected screenshots, clipboard contents, VPN and Wi-Fi information, messaging and email application data, and general host profiling information. Stealerium additionally supports keylogging and clipper behavior, enabling interception of keystrokes and replacement of copied cryptocurrency wallet addresses. Exfiltration has been observed through multiple channels, including Discord webhooks, Telegram, SMTP, FTP, and related mechanisms depending on the build and operator configuration.
A notable feature associated with Stealerium is NSFW-triggered surveillance intended to support sextortion or blackmail. When configured to detect adult-themed keywords in an active browser tab, the malware can capture a desktop screenshot and a webcam image. This capability distinguishes it from many commodity stealers that focus primarily on credential and wallet theft.
Stealerium has frequently appeared in phishing-delivered infections and in social-engineering chains that rely on user execution rather than software exploitation. Observed delivery patterns include malicious archives, script-based droppers, PowerShell loaders, and ClickFix-style lures. Because the project is openly available, many campaigns involve customized forks that add obfuscation, process injection, persistence, anti-analysis, or bespoke loaders while retaining Stealeriumโs theft modules and configuration structure.
The malware primarily targets Windows systems. Its open-source availability and modular design have lowered the barrier to entry for threat actors, making it a recurring component in commodity credential-theft operations and a common ancestor for more heavily weaponized infostealer variants.
C2 tracking
Derp observations, rolling seven-day window
Samples
2eea097e689004e05f44f04ff22909c96d43d04fa7e5936f3709cf0d3a36c041 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 265ff3e568105a01f8c6d52912715be58f550096b12332fdc86c7c4e80746323 3a297d846199ddff323b30eadb510daedbbd08a9e76949c06df09e1592dd0f02 73bc2ee1c189d5798b8006db976f07ea7f21be8c7f8e4d810e1ac5f7aeb4aa5b 7584a1b0daf329afd2123a71dadb54abb9fe353838b33cc2469506859145f588 7ad69e000cd4f0854fd444a4973da7d14db8d86103394d267efb9f96323ca263 2870b115f689a226c79cc1428ed2c1cb8b118850bfa21401a397de22ad9250e6 Reported operators
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
... delivering an open-source information stealer called Stealerium (or variants of it).
... delivering an open-source information stealer called Stealerium (or variants of it).
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.