RisePro is a Windows information-stealing malware family first observed in 2022 and commonly tracked as an infostealer offered and operated in cybercriminal ecosystems. It is designed to collect credentials, browser cookies, saved payment-card data, cryptocurrency wallet data, screenshots, host fingerprinting information, and selected files from infected systems. Targeted applications include major Chromium- and Gecko-based browsers, browser extensions associated with cryptocurrency wallets and two-factor authentication, and desktop applications such as Discord, battle.net, and Authy Desktop. RisePro also searches for wallet artifacts associated with multiple cryptocurrency clients and can package stolen data into archives for exfiltration.
The malware uses string and API obfuscation, dynamic import resolution, and in some cases embedded or remotely fetched legitimate DLLs to access browser data. It stages collected information in a temporary working directory, compresses the results, and communicates with command-and-control infrastructure over obfuscated HTTP using JSON-like messages protected with byte-substitution and XOR-based encoding. Reported command functionality includes retrieval of settings, grabber rules, and libraries, and available configuration indicates support for features such as screenshot capture, wallet theft, and collection of network-history data. Some analysis has suggested a possible loader capability, although that functionality has not been consistently observed in execution.
RisePro has been repeatedly associated with PrivateLoader-delivered infections, and multiple analyses have noted code, protocol, and infrastructure similarities between the two malware families, while stopping short of confirming a definitive development relationship. It has also appeared in multi-payload crimeware chains alongside other stealers and commodity malware. In observed Windows intrusions, RisePro established persistence through scheduled tasks and startup shortcuts, sometimes configured to run at logon and with elevated privileges.
Distribution has been linked to cracked-software lures, including fake installers and repositories masquerading as pirated software projects, as well as broader malware delivery ecosystems that use loaders to inject RisePro into legitimate Windows processes. RisePro has also been cited among infostealers whose stolen credentials were later abused in follow-on compromises, including access to enterprise services. The malware is widely recognized in the stealer landscape for theft of passwords, payment data, and cryptocurrency-related information from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks... (T1053.005 – Scheduled Task/Job: Scheduled Task).
During execution, the loader connects to hxxp://176.113.115(dot)227:56385/31522 and injects its payload [4] into either AppLaunch.exe or RegAsm.exe.
To complicate analysis, this file [3] is bloated to 699 MB which causes IDA and ResourceHacker to crash... The file is obfuscated with a version of .NET Reactor 6 and has virtualization enabled... RisePro uses XOR obfuscated stack strings.
TTPs Table 3. MITRE ATT&CK TTPs for RisePro Stealer ... Defense Evasion T1027.005 – Obfuscated Files or Information: Indicator Removal from Tools
The sample resolves its imports dynamically using import hashing with Fowler–Noll–Vo hash 1A.
The repositories look similar, featuring a README.md file with the promise of free cracked software. Green and red circles are commonly used on Github to display the status of automatic builds. Gitgub threat actors added four green Unicode circles to their README.md that pretend to display a status alongside a current date and provide a sense of legitimacy and recency.
During execution, the loader connects to hxxp://176.113.115(dot)227:56385/31522 and injects its payload [4] into either AppLaunch.exe or RegAsm.exe.
Host fingerprinting RisePro Stealer has a fingerprint capability, all information are retrieved in the following registry keys
TTPs Table 3. MITRE ATT&CK TTPs for RisePro Stealer ... Discovery T1033 – System Owner/User Discovery
TTPs Table 3. MITRE ATT&CK TTPs for RisePro Stealer ... Discovery T1057 – Process Discovery
Host fingerprinting RisePro Stealer has a fingerprint capability
The stealer also looks for particular file patterns, for example receipt with credit card information in common folders (for instance, Desktop, Download, %TEMP%).
TTPs Table 3. MITRE ATT&CK TTPs for RisePro Stealer ... Discovery T1087 – Account Discovery
The purpose is to evade analysis environments with time-based methods, and the Windows Task Scheduler can be abused... (T1497.003 – Virtualization/Sandbox Evasion: Time Based Evasion, and T1053.005 – Scheduled Task/Job: Scheduled Task).
The stealer targets cookies, saved passwords, saved credit cards and crypto wallets and also installed softwares for credentials.
The sample communicates with a C2 server in a manner similar to what was discovered in November 2023... The threat actors have not changed their approach and are still using primarily TCP port 50500.
325 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family distributed by the same loader ecosystem as StealC.
Referenced only as another stealer compared against OnyxC2.
Инфостилер, для которого характерным артефактом является файл passwords.txt.
Инфостилер, упомянутый как один из вариантов, обеспечивавших поток украденных учётных данных для кампании против Snowflake.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.