Skip to content

Infostealer

ColdStealer

ColdStealer is a relatively new malicious program that was discovered in 2022.

ColdStealer is a Windows infostealer.

Background

ColdStealer is a fairly recent threat first seen in 2022. As with many stealers, its core aim is to lift credentials and data from web browsers, while also grabbing cryptocurrency wallets, FTP credentials, assorted files, and system details such as the OS version, system language, processor type, and clipboard contents. Rather than writing the harvested data to files, the stealer assembles it as a ZIP in memory, helping it dodge detection by leaving no file or execution traces behind. The only documented exfiltration method is transmitting that ZIP archive to a hardcoded command and control (C2) server.


Source: Malpedia (Fraunhofer FKIE).