PULSE NAME
MicroStealer
WHITE GameOver Zeus PetrP.73 2026-05-08 Modified: 2026-05-08
29
IOCs
MEDIUM VOLUME
MicroStealer has emerged as a sophisticated infostealer malware, first identified in late 2025, that targets sensitive information such as browser credentials, session cookies, cryptocurrency wallet data, and desktop screenshots. Its delivery mechanism utilizes a multi-stage chain comprising NSIS installers, Electron applications, and Java payloads, making it challenging to detect using traditional methods. Notably, it employs dual-channel exfiltration techniques-both through Discord webhooks and attacker-controlled servers, to ensure data is sent even if one channel becomes compromised.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
MicroStealer Qilin IcedID
Indicators of Compromise (29)
All IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 213.142.135.175 CC=TR ASN=AS207429 kapteyan bilisim teknolojileri san. ve tic. a.s. 2026-05-08
IPv4 213.142.135.203 CC=TR ASN=AS207429 kapteyan bilisim teknolojileri san. ve tic. a.s. 2026-05-08
IPv4 45.145.42.77 CC=US ASN=AS19120 infocube technology limited 2026-05-08
domain arcaneharbor.com 2026-05-08
domain crushfall.com 2026-05-08
domain eclipsewarden.com 2026-05-08
domain elvarioth.com 2026-05-08
domain epicdepths.com 2026-05-08
domain feridogames.com 2026-05-08
domain klozerus.com 2026-05-08
domain leynara.com 2026-05-08
domain loot-rush.com 2026-05-08
domain nightsthread.com 2026-05-08
domain seylaran.com 2026-05-08
domain shadowcape.com 2026-05-08
domain swordfull.info 2026-05-08
domain velarith.com 2026-05-08
domain zarvethion.com 2026-05-08
hostname www.slumpcute.com 2026-05-08
IPv4 64.29.17.65 2026-05-08
IPv4 150.171.22.17 2026-05-08
IPv4 172.211.123.249 2026-05-08
IPv4 195.177.94.253 2026-05-08
IPv4 68.211.144.54 2026-05-08
IPv4 150.171.22.254 2026-05-08
IPv4 162.159.138.232 2026-05-08
IPv4 40.126.31.3 2026-05-08
IPv4 13.107.18.254 2026-05-08
IPv4 13.107.213.45 2026-05-08