ZingoStealer is a .NET-based Windows information stealer associated with the crimeware group Haskers Gang and first observed in 2022. It was promoted in Russian-speaking cybercrime communities and distributed free to members of the group’s Telegram ecosystem, which contributed to rapid adoption and active iterative development. Campaigns primarily targeted home users, especially Russian-speaking victims, using lures themed around game cheats, cracks, key generators, pirated software, and similar illicit downloads.
The malware collects a broad range of victim data, including browser-stored credentials and cookies, system profiling information, screenshots, collaboration-platform tokens, cryptocurrency wallet extension data, desktop wallet data, and files from the user desktop. It stages the stolen material locally, compresses it into an archive, and exfiltrates it to operator-controlled infrastructure. ZingoStealer also uses Telegram-centric workflows for build distribution and handling of stolen logs.
Beyond core infostealing, ZingoStealer functions as a loader for additional payloads. Observed secondary payloads include RedLine Stealer and an XMRig-based Monero mining component referred to as ZingoMiner, enabling operators to further monetize compromised hosts. The mining component has been observed adding Defender exclusions, establishing persistence through scheduled tasks, and injecting the miner into another process. Reporting also indicates geolocation-based logic consistent with avoiding victims in CIS countries. ZingoStealer has additionally been offered with the ExoCrypt crypter service to improve evasion. Ownership of the project was later advertised as being transferred, and the source code was offered for sale, indicating its role as a commodity crimeware tool rather than a tightly controlled bespoke implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos recently observed a new information stealer, called "ZingoStealer" that has been released for free by a threat actor known as "Haskers Gang."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
This feature was added in a recent release, and uses PowerShell to add the necessary exclusions on Windows Defender and execute the miner.
In many cases, ZingoStealer is currently being distributed under the guise of game cheats, cracks and code generators.
A new information-stealing malware called ZingoStealer has been discovered with powerful data-stealing features... From a data-stealing perspective, this is a potent malware targeting the following apps and data points...
The malware also attempts to enumerate environmental and system information. This data is saved within a text file called "system.txt"
ZingoStealer also attempts to access information related to Chrome extensions that may be present within the victim's web browser.
The stealer then creates a directory structure which is used to collect and save sensitive information that is later exfiltrated to the attacker.
A new information-stealing malware called ZingoStealer has been discovered with powerful data-stealing features... From a data-stealing perspective, this is a potent malware targeting the following apps and data points...
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a possible behavioral comparison for some exfiltration activity; the article explicitly says it cannot fully attribute the activity to ZingoStealer.
An information-stealing .NET malware promoted in Russian-speaking cybercrime channels that steals browser, wallet, and system data, exfiltrates it to an operator server, performs a CIS geolocation check, can retrieve and execute second-stage payloads, and can deploy XMRig to mine Monero.
An information stealer first seen in March 2022 that steals credentials, browser data, crypto wallet information, Discord/Telegram tokens, screenshots, and system information; exfiltrates data via attacker infrastructure and Telegram workflows; and also acts as a loader for secondary payloads including RedLine Stealer and XMRig-based mining malware.
An information stealer first seen in March 2022 that steals credentials, browser data, collaboration-platform tokens, cryptocurrency wallet data, screenshots, and system information, exfiltrates data via attacker infrastructure and Telegram workflows, and also downloads and executes secondary payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.