Skip to content

Infostealer

KiwiStealer

According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024.

KiwiStealer is a Windows infostealer operated by HAZY TIGER.

Background

Threatray describes KiwiStealer as a basic file stealer first identified in late 2024. It begins by collecting the computer name and username, and also reads the current system time, which it later uses to compare against files' last-modification timestamps. KiwiStealer walks a fixed set of directories looking for files, exfiltrating only those under 50MB that were modified within the previous year. The extensions it targets are: z7, .txt, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .jpg, .zip, .rar, .apk, .neat, .err, .eln, .ppi, .er9, .azr, .pfx, .ovpn.


Source: Malpedia (Fraunhofer FKIE).