PULSE NAME
Arkanix Stealer: Newly discovered short term profit malware
WHITE AlienVault 2025-12-01 Modified: 2025-12-01
3
IOCs
LOW VOLUME
A new information stealer named Arkanix has emerged, likely designed for short-term financial gains. Advertised on Discord, it has rapidly evolved from a Python-based to a C++ version. The malware steals data from various browsers, crypto wallets, VPN accounts, and system information. It employs sophisticated techniques like VMProtect for obfuscation and 'Chrome Elevator' to bypass App Bound Encryption. Arkanix is distributed through Discord and online forums, disguised as legitimate tools. The threat actors offer a web panel with premium features, including VPN and Steam account theft. This case highlights the ease of starting cybercrime businesses for quick profits, with actors demonstrating considerable experience in malware development and distribution.
Indicators of Compromise (3)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 6960d27fea1f5b28565cd240977b531cc8a195188fc81fa24c924da4f59a1389 2025-12-01
FileHash-SHA256 6ea644285d7d24e09689ef46a9e131483b6763bc14f336060afaeffe37e4beb5 2025-12-01
domain arkanix.pw 2025-12-01