Stealerium is an open-source .NET information stealer written in C# that emerged in 2022 and has been widely reused, modified, and operationalized in criminal campaigns. It is best known as an infostealer with additional keylogging and cryptocurrency clipper functionality, and it has served as the codebase foundation for related malware such as Phantom Stealer and Enigma Stealer. Security reporting has repeatedly linked Stealerium-family malware to financially motivated activity, including phishing and ClickFix-style social-engineering campaigns, as well as broader commodity malware ecosystems targeting enterprise users and individuals.
Core Stealerium functionality includes theft of browser-stored credentials, cookies, session tokens, cryptocurrency wallet data, and other sensitive application data from compromised Windows systems. Reported variants and forks have also collected screenshots, clipboard contents, VPN and Wi-Fi information, messaging and email application data, and general host profiling information. Stealerium additionally supports keylogging and clipper behavior, enabling interception of keystrokes and replacement of copied cryptocurrency wallet addresses. Exfiltration has been observed through multiple channels, including Discord webhooks, Telegram, SMTP, FTP, and related mechanisms depending on the build and operator configuration.
A notable feature associated with Stealerium is NSFW-triggered surveillance intended to support sextortion or blackmail. When configured to detect adult-themed keywords in an active browser tab, the malware can capture a desktop screenshot and a webcam image. This capability distinguishes it from many commodity stealers that focus primarily on credential and wallet theft.
Stealerium has frequently appeared in phishing-delivered infections and in social-engineering chains that rely on user execution rather than software exploitation. Observed delivery patterns include malicious archives, script-based droppers, PowerShell loaders, and ClickFix-style lures. Because the project is openly available, many campaigns involve customized forks that add obfuscation, process injection, persistence, anti-analysis, or bespoke loaders while retaining Stealerium’s theft modules and configuration structure.
The malware primarily targets Windows systems. Its open-source availability and modular design have lowered the barrier to entry for threat actors, making it a recurring component in commodity credential-theft operations and a common ancestor for more heavily weaponized infostealer variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
... delivering an open-source information stealer called Stealerium (or variants of it).
... delivering an open-source information stealer called Stealerium (or variants of it).
12 distinct techniques documented for this family, organized by ATT&CK tactic.
This campaign is a textbook example... combining open-source code (Stealerium base), deep obfuscation, and skilled loader engineering... pushing the boundary of what’s possible with “just scripts”
"trick users into executing PowerShell commands that deploy the StealC information stealer"; "instruct the victim to run a PowerShell command ... resulting in ... Stealerium"
The script’s surface was a tangled web of Chr() arithmetic, farm-themed variable names, and aggressive string concatenation... Junk strings replace executable commands... split into multiple fragments and littered with “mango”/“avocadopapaya” to defeat automated forensics.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
It then starts to collect system information and steals user information, tokens, and passwords from various web browsers and applications
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source .NET infostealer project that served as the codebase/foundation for Phantom Stealer. It appears to be a simpler precursor without the larger embedded SQLite and BouncyCastle components described for Phantom Stealer.
Referenced as the malware family lineage from which PhantomStealer derives. It provides a modular collector-plus-exfiltration architecture inherited by PhantomStealer.
Commodity stealer used alongside Infy’s proprietary malware.
Open-source .NET infostealer delivered after a ClickFix flow initiated by phishing with a malicious SVG inside a password-protected ZIP, leading the victim to run a PowerShell command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.