Skip to content

Infostealer

Stealerium

According to SecurityScorecard, Stealerium is an open-source stealer available on GitHub.

Stealerium is a Windows infostealer.

Background

SecurityScorecard describes Stealerium as an open-source stealer distributed publicly on GitHub. It harvests data from browsers, cryptocurrency wallets, and a range of applications including Discord, Pidgin, Outlook, Telegram, Skype, Element, Signal, Tox, Steam, Minecraft, and VPN clients. Beyond credentials, it profiles the victim machine by collecting running processes, Desktop and webcam captures, nearby Wi-Fi networks, the Windows product key, and both public and private IP addresses. To resist examination, the malware checks for virtual machines, sandboxes, and analysis tooling, and verifies whether it is being debugged. It additionally bundles a keylogger and a clipper that swaps any cryptocurrency wallet address the victim copies for one belonging to the attacker, with all collected data exfiltrated to a Discord channel through a Discord Webhook.


Source: Malpedia (Fraunhofer FKIE).