Phemedrone is an open-source C# information-stealing malware family used to harvest credentials and other sensitive data from Windows systems. It has been distributed primarily through Telegram ecosystems and was previously available on GitHub, making it easy for low- to mid-tier actors to adopt, modify, and rebrand. Variants and repurposed builds have appeared in broader crimeware campaigns, including fake software, cheat, and crack distribution, and it has also been referenced as a close technical relative of Ov3r_Stealer.
Phemedrone targets browser-stored data from Chromium- and Gecko-based browsers, including passwords, cookies, credit card data, and autofill information. It also targets browser extensions associated with cryptocurrency wallets, password managers, and authenticators. Beyond browsers, it steals Discord tokens, cryptocurrency wallet data, Telegram account data, Steam files, FileZilla data, VPN-related information, screenshots, local files from user directories, and host profiling data such as geolocation, hardware, installed security products, and other system metadata. The malware is notable for parsing stolen browser data on the victim host and organizing results into operator-friendly tagged categories, including tags oriented toward financial and service accounts.
The family supports multiple exfiltration models, including Telegram-based delivery as well as gate and panel senders. Telegram has been observed both as an exfiltration channel and as part of the surrounding criminal ecosystem used to distribute and operate the malware. Phemedrone also includes anti-analysis features such as anti-debugging, anti-virtualization checks, mutex logic, and an optional CIS keyboard-language exclusion. Reporting also indicates that Phemedrone has been among the malware families able to bypass Chromium App-Bound Encryption protections.
Phemedrone is widely regarded as an infostealer rather than a remote administration tool, although it is sometimes discussed alongside commodity RATs because of overlapping criminal distribution channels and operator communities. Its open-source nature, frequent customization, and reuse in rebranded campaigns have made attribution difficult and have contributed to a growing set of variants in the wild.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
They started distributing malware under the guise of restriction bypass programs and injecting malicious code into existing programs.
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Phemedrone will target Discord tokens by accessing the Discord leveldb database, stored on a victim’s computer. It will then regex for “dQw4w9WgXcQdQw4w9WgXcQ:[^\”]*”, which it will use to extract the victim’s Discord token for authentication purposes.
Phemedrone steals data from the internal Chromium/Firefox storage databases that store passwords, credit cards, cookies, and more.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Anti-VM Phemedrone’s anti-VM check checks the victim’s computer for the following virtual machine (VM) strings, which indicate that Phemedrone is being run in a VM.
Phemedrone also includes a basic filegrabber, which will iterate through My Documents and Desktop and steal all files based on config supplied max file size and directory depth.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
Stealer malware that gathers victim network and geolocation information by querying external IP-lookup services such as ip-api.com.
A named malware family (and variants) distributed through malicious YouTube videos/links in the “YouTube Ghost Network” operation; specific functionality is not described in the provided content.
Named information-stealing malware listed as detectable via favicon hash hunting of exposed infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.