MonsterV2 is a subscription-based Windows malware family sold in criminal markets and commonly characterized as a multifunctional stealer with remote-access and payload-delivery features. It has been described as a RAT, loader, backdoor, and infostealer, with observed use by cybercrime operators including TA585 and delivery through broader malware ecosystems such as CastleLoader. The malware is also known as Aurotun Stealer.
MonsterV2 is designed to steal a wide range of victim data, including account credentials, browser-stored information, cryptocurrency wallet data, payment-card data, authentication tokens, personally identifiable information, and files. Reported token theft includes services such as messaging, gaming, and communication platforms. In addition to theft functions, it supports command execution, download-and-execute of additional payloads, desktop viewing, webcam capture, hidden virtual network computing for covert remote desktop control, and clipboard manipulation for cryptocurrency address replacement. It has also been observed loading secondary malware families.
Operationally, MonsterV2 has been tied to social-engineering-heavy intrusion chains rather than software exploitation. A prominent delivery pattern uses ClickFix-style lures in phishing or compromised-website campaigns, where victims are shown fake CAPTCHA or verification overlays and tricked into manually executing PowerShell commands that retrieve and install the malware. TA585 has used such chains with government-themed email lures and with abused GitHub notification workflows. MonsterV2 has also been distributed by CastleLoader alongside other commodity stealers and remote-access tools.
The malware appears actively maintained and includes anti-analysis and regional filtering behavior. Reported samples avoid infecting systems in CIS countries. MonsterV2 is frequently packed with SonicCrypt, which adds environment checks and complicates analysis before the payload is decrypted and launched. Overall, MonsterV2 occupies the increasingly common criminal niche of a modular MaaS stealer that blends credential and financial theft with hands-on remote access and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The main malware payload used by TA585 is MonsterV2, a backdoor, stealer and loader MaaS.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
On website load, the malicious injection causes a script to run that forces an overlay to appear on the infected website.
The ClickFix phishing campaign sends users an email claiming they must confirm their identity to maintain access to their email account.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an infostealer family distributed by CastleLoader.
An infostealer delivered via a ClickFix phishing campaign that tricks users into running a malicious script from a compromised legitimate website. It steals cryptocurrency wallets, account credentials, personally identifiable information, and browser data.
MonsterV2 is a malware family distributed via the CastleLoader framework.
Subscription-based MaaS malware family advertised in Feb 2025. Delivered via ClickFix social engineering (victim copy/pastes PowerShell), then installs to steal credentials/tokens/crypto wallet data and provides hidden remote control via HVNC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.