← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Arkanix Stealer: Newly discovered short term profit malware
A new information stealer named Arkanix has emerged, likely designed for short-term financial gains. Advertised on Discord, it has rapidly evolved from a Python-based to a C++ version. The malware steals data from various browsers, crypto wallets, VPN accounts, and system information. It employs sophisticated techniques like VMProtect for obfuscation and 'Chrome Elevator' to bypass App Bound Encryption. Arkanix is distributed through Discord and online forums, disguised as legitimate tools. The threat actors offer a web panel with premium features, including VPN and Steam account theft. This case highlights the ease of starting cybercrime businesses for quick profits, with actors demonstrating considerable experience in malware development and distribution.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 6960d27fea1f5b28565cd240977b531cc8a195188fc81fa24c924da4f59a1389 | — | 2025-12-01 | |
| FileHash-SHA256 | 6ea644285d7d24e09689ef46a9e131483b6763bc14f336060afaeffe37e4beb5 | — | 2025-12-01 | |
| domain | arkanix.pw | — | 2025-12-01 |