Related tools tied to the same developer include TheVoidStealer, WallStealer, and Void Miner, suggesting an active and steadily expanding malware portfolio.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
WallStealer in ATT&CK
14 distinct techniquesTechniques
14 techniquesReporting
Research mentioning WallStealer
Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner - Ctrl-Alt-Intel
Researchers identified an exposed server at 94[.]103[.]1[.]175:16482 hosting counterfeit Cloudflare verification pages that use a ClickFix-style CAPTCHA lure. The pages attempt to copy an obfuscated PowerShell command to a visitor’s clipboard and persuade them to run it, leading to a protected executable hosted on the same infrastructure. Two Rust droppers unpacked near-identical WallStealer payloads designed to collect browser credentials, cookies, payment information, screenshots, system details, and data from messaging, gaming, FTP, and cryptocurrency-wallet applications. WallStealer uses Steam profile persona names as dead-drop resolvers to obtain command-and-control destinations, complicating infrastructure tracking. Investigators also found stube.exe, a loader containing an XMRig 6.25.0-derived mining DLL configured to connect to 94[.]103[.]1[.]175:3333, tying cryptomining capability to the same delivery environment. The samples were analyzed statically without execution or infrastructure interaction, and defects in purported delivery scripts prevented confirmation that the campaign successfully infected victims.