Stealer Service
Closed channel
🚩 Channel was restricted by Telegram
Show more5 897
Subscribers
No data24 hours
-617 days
-23830 days
Posts Archive
5 897
+1
Kaspersky Lab published stealer statistics for the past year.
According to them, over the past 4 years more than 100 varieties of stealers have appeared. RedLine remains the most effective and popular - 55% of all attacks occur with its help. Vidar came in second place with 17%, and Raccoon rounded out the top three with 12% of all attacks. Starting in 2021, the growth in new stealers has increased by 28%. Previously it was only 4%.
Private: @StealerStoreBot
Malware Shop: @MalwareShopBot
All Projects @MalwareLinks
5 897
RDP Credential Stealer
HowToUse:
https://github.com/S12cybersecurity/RDPCredentialStealer#proof-of-concept-tool-for-credential-theft
https://github.com/S12cybersecurity/RDPCredentialStealer/releases
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
White Snake stealer 1.6.1.1
Fixed errors with large log files.
Increased speed of log decompression/parsing.
Linux stub fixes.
Zip converter fixes.
Cleaned WD detect.
Updated C2 list.
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
White Snake stealer 1.6.0.7 (patch №3)
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Rhadamanthys Stealer v0.4.1
https://telegra.ph/Rhadamanthys-Stealer-07-06
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
EdgeGuard Stealer v4
Screenshot:
https://t.me/WhatTheFileBot?start=AAbAKr1sAzJv0beKkJcLEFQxDAA4zBAUpF5sgSADBbpgfAsIgpSAjC
Features:
Private Stub Coded From Scratch [ C/Golang ]
Steals Screenshot Of Desktop
Steals Wallets [ Atomic,Exodus, MetaMask ]
Steals Passwords [ Supports All Browsers ]
Steals Cookies [ Chrome,Firefox ]
Steals Browser History
Steals Browser Downloads
Steals TaskSch List.
Steals Social Network Passwords
Steals Website Login Passwords
Steals FTP Login Details
Steals RDP Details
Steals Microsoft Outlook 2003 To 2023
Steals WindowsMail
Steals Windows Live Mail
Steals AOL Mail
Steals Proton Mail
Steals Gmail/Yahoo/Outlook Mails
Steals Foxmail/Thunderbird
Steals Apple Mail
Steals Wifi Pass
Steals DataBase Manager Passwords
More.
Status Cryptable With Any Crypter, The Crypter Must Support x64 Bit files.
Use UPX Packer To Lower Size Of The Executable
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Invicta Stealer — a powerful, native stealer
This is a C++ stealer which is being actively improved upon, with the help we receive from our active community.
BROWSERS
Information is obtained from all the profiles from all chromium-based (the most used) browsers, and firefox.
We collect: credit card data, autofill, history, all extensions which include 71 crypto wallets and various authenticators, local storage, downloads, and much more. Essentially, all the information is collected.
DISCORD
All of the discord tokens are extracted from: the regular client, discord canary, ptb discord and browser local storage
CRYPTO
Wallet information is collected from 25 wallets, with new ones being actively added.
SENSITIVE DIRECTORIES AND FILES
We have studied real world scenarios, and came up with advanced filters that will fetch you sensitive information related to cryptocurrency wallets, bank accounts, passwords, private keys, etc.
The stealer gets recently opened .txt files, recursively iterates through the computer to find sensitive information, steals github and visual studio code repositories (with bloat removed), gets .txt files from desktop, documents, etc
FTP CLIENTS
Information is obtained from WinSCP and FileZilla
SYSTEM INFORMATION
We collect system information, which includes the HWID, IP, timezone, computer language, RAM, CPU information, etc
ANTI-DEBUGGING, EVASION TECHNIQUES
We use anti-debug/anti-virustotal/anti-vm techniques which complicate analysis of the malware. Your link will be encrypted in the stealer file.
Sensitive operations are performed through syscalls, which make them harder to detect by AVs and analysts, and all strings are encrypted.
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Klimt Stealer Source Code #GO
The most powerful credential & information stealing tool, written in GoLang
Features:
Credential Stealing:
Discord Stealer: Steals authentication tokens and account information from 30+ Discord locations.
Wallet Stealer: Steals cryptocurrency wallet files and credentials from popular wallets.
FileZilla Stealer: Steals recent server credentials and configuration settings from the FileZilla client.
Browser Stealer: Steals browser cookies, passwords, history, downloads and credit cards from Web Browsers.
Program Injection:
Discord: Injects a custom Javascript package into the Discord process for added functionality.
General: Collects general system information using the Windows registry and WMIC.
Local Files: Scans the target machines files.
Installed Software: Collects information on installed software.
Network Connections: Logs network activity and connections.
Misc:
Reverse Shell: Optional connection to your external listener server (netcat, msf, etc.)
Custom GUI Builder with interactive widgets (Embed color picker, tabs, etc.)
Relatively small build size (4MB UPX'd) in comparison to other stealers (approx. 30MB+)
FUD With Crypter (Pro version is less detectable)
Encrypts strings stored in the config so that they aren't searchable in the binary, such as:
Discord Webhook URL
Reverse Shell Server Information
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
W4SP Stealer Source Code, With Api And Bot
Features:
Saved Passwords
Browser Cookies
Get PC information
AntiVM - Trust Factor system, it wont send data if Gmail cookies arent' found
All files are uploaded to an external api <- Improved by xKian
Data is send throught a Discord webhook
Discord Tokens from browsers
Discord Token from discord, discordcanary, discordPTBa
Get all info on token (email, nitro/badge, rare friends)
Wallets
Exodus Wallet
Metamask Wallet
Atomic Walletk
Steam Client
Riot Client
NationsGlory Client
Telegram Session
File Stealer
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Rust Stealer upd #rust
Small update:
- Changed Mutex
- Stealer now deletes all traces after grab
- Fixed a bug on the sensitive files grabber.
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Rust Stealer V3 source code #rust
The first version of the style on Rust Logs are delivered to telegram.
Features:
Chrome (Cookies, History, Passwords)
Extension
Sensitive Data Stealer
Steam & Telegram Stealer
Systeminfo (Running Processes, screenshots etc...)
Wallet Stealer:
AtomicWallet, Exodus, Jaxxwallet, Electrum, ByteCoin
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Rust Stealer V2 source code #rust
The first version of the style on Rust Logs are delivered to telegram.
Features:
Chrome (Cookies, History, Passwords)
Extension
Sensitive Data Stealer
Steam & Telegram Stealer
Systeminfo (Running Processes, screenshots etc...)
Wallet Stealer:
AtomicWallet, Exodus, Jaxxwallet, Electrum, ByteCoin
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Rust Stealer V1 source code #rust
The first version of the style on Rust Logs are delivered to telegram.
Features:
Chrome (Cookies, History, Passwords)
Extension
Sensitive Data Stealer
Steam & Telegram Stealer
Systeminfo (Running Processes, screenshots etc...)
Wallet Stealer:
AtomicWallet, Exodus, Jaxxwallet, Electrum, ByteCoin
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
CheckTgBot - крадём логи с чужого стиллера
Воруем прежде ворованные данные. Круто ведь?)
Приступим:
1. Устанавливаем CheckTgBot
2. Ищем стиллеры с отправкой данных в телеграм бота. Придётся качать кучу вирусняков на виртуалку/песочницу. Я их находил так: вводим в ютуб "известная игра + чит + скачать бесплатно", ищем левые ссылки и скачиваем всё подряд.
3. Скачиваем HTTP Debugger, открываем стиллер и мониторим запросы стиллера. Если удастся найти нужный нам стиллер, в дебаггере мы увидим данные с API Telegram бота, который нам и нужен.
4. Открываем CheckTgBot, вводим API и ID бота. Софт выдаст нам юзернейм бота, который использует чужой стиллер. Стартуем этого бота в телеграме.
Софт спросит, с какого сообщения нужно начать пересылать нам, вводим 0.
Получаем все данные. Если владелец ничего не заметит, то мы продолжим перехватывать новые данные.
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Gomorrah stealer v5 C2 Panel
REF - https://www.broadcom.com/support/security-center/protection-bulletin?#blt1a691f9acd8408b9_en-us
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Growtopia Stealer C#
Features:
Steal UserName
Steal Machine Name
Show active windows
Show path where file was started
Show Operating system
Show screen metrics
Show CPU
Show GPU
Show RAM
Steal BSSID
Show IP
Show IPv6
Show Country
Show City
Steal MAC Address
Show Clipboard
Steal Discord Tokens from Discord App, DiscordCanary App, DiscordPTB App, Chrome Browser, Chrome Beta Browser,FireFox Browser, Opera Browser, OperaGX Browser, Edge Browser, Yandex Browser, Brave Browser,Vivaldi Browser, Epic Privacy Browser, 360Browser, CocCoc Browser.
Steal Growtopia save.dat
Show GrowID and Password
Show Screenshot
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
Mercurial Grabber Builder C#
Features:
Grabs Roblox cookies from Roblox Studio
Grabs Minecraft sessions
Grabs Google Chrome passwords
Grabs Google Chrome cookies
Grabs Discord token
Grabs victim machine info
Grabs Windows product key
Grabs IP address, geolocation
Grabs screenshot
Anti Virutal Machine
Anti Debug
Customization:
Add a custom icon
Custom exe name
Screenshot:
https://user-images.githubusercontent.com/75003671/120157017-26796300-c225-11eb-8f84-7428165ca672.gif
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
5 897
WorldWind Stealer v2.04. Cracked
How to use?
BOT API TOKEN: Go to @Botfather and create a telegram bot and then put the api in the first box
Chat ID: get your chat id from @chatid_echo_bot and paste it in the 2nd box
Then go to your telegram bot that you created it and start it build your virus and spread it and you will get your result on your bot
Archive password: @stealerstore
💬 Stealer Developers
Private: @StealerStoreBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
