← Back to Pulse Feed
PULSE DETAIL
MicroStealer has emerged as a sophisticated infostealer malware, first identified in late 2025, that targets sensitive information such as browser credentials, session cookies, cryptocurrency wallet data, and desktop screenshots. Its delivery mechanism utilizes a multi-stage chain comprising NSIS installers, Electron applications, and Java payloads, making it challenging to detect using traditional methods. Notably, it employs dual-channel exfiltration techniques-both through Discord webhooks and attacker-controlled servers, to ensure data is sent even if one channel becomes compromised.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| IPv4 | 213.142.135.175 | CC=TR ASN=AS207429 kapteyan bilisim teknolojileri san. ve tic. a.s. | 2026-05-08 | |
| IPv4 | 213.142.135.203 | CC=TR ASN=AS207429 kapteyan bilisim teknolojileri san. ve tic. a.s. | 2026-05-08 | |
| IPv4 | 45.145.42.77 | CC=US ASN=AS19120 infocube technology limited | 2026-05-08 | |
| domain | arcaneharbor.com | — | 2026-05-08 | |
| domain | crushfall.com | — | 2026-05-08 | |
| domain | eclipsewarden.com | — | 2026-05-08 | |
| domain | elvarioth.com | — | 2026-05-08 | |
| domain | epicdepths.com | — | 2026-05-08 | |
| domain | feridogames.com | — | 2026-05-08 | |
| domain | klozerus.com | — | 2026-05-08 | |
| domain | leynara.com | — | 2026-05-08 | |
| domain | loot-rush.com | — | 2026-05-08 | |
| domain | nightsthread.com | — | 2026-05-08 | |
| domain | seylaran.com | — | 2026-05-08 | |
| domain | shadowcape.com | — | 2026-05-08 | |
| domain | swordfull.info | — | 2026-05-08 | |
| domain | velarith.com | — | 2026-05-08 | |
| domain | zarvethion.com | — | 2026-05-08 | |
| hostname | www.slumpcute.com | — | 2026-05-08 | |
| IPv4 | 64.29.17.65 | — | 2026-05-08 | |
| IPv4 | 150.171.22.17 | — | 2026-05-08 | |
| IPv4 | 172.211.123.249 | — | 2026-05-08 | |
| IPv4 | 195.177.94.253 | — | 2026-05-08 | |
| IPv4 | 68.211.144.54 | — | 2026-05-08 | |
| IPv4 | 150.171.22.254 | — | 2026-05-08 | |
| IPv4 | 162.159.138.232 | — | 2026-05-08 | |
| IPv4 | 40.126.31.3 | — | 2026-05-08 | |
| IPv4 | 13.107.18.254 | — | 2026-05-08 | |
| IPv4 | 13.107.213.45 | — | 2026-05-08 |
References (1)