PULSE NAME
MicroStealer
WHITE GameOver Zeus PetrP.73 2026-05-08 Modified: 2026-05-08
29
IOCs
MEDIUM VOLUME
MicroStealer has emerged as a sophisticated infostealer malware, first identified in late 2025, that targets sensitive information such as browser credentials, session cookies, cryptocurrency wallet data, and desktop screenshots. Its delivery mechanism utilizes a multi-stage chain comprising NSIS installers, Electron applications, and Java payloads, making it challenging to detect using traditional methods. Notably, it employs dual-channel exfiltration techniques-both through Discord webhooks and attacker-controlled servers, to ensure data is sent even if one channel becomes compromised.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
MicroStealer Qilin IcedID
Indicators of Compromise (15 / 29 total)
All IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain arcaneharbor.com 2026-05-08
domain crushfall.com 2026-05-08
domain eclipsewarden.com 2026-05-08
domain elvarioth.com 2026-05-08
domain epicdepths.com 2026-05-08
domain feridogames.com 2026-05-08
domain klozerus.com 2026-05-08
domain leynara.com 2026-05-08
domain loot-rush.com 2026-05-08
domain nightsthread.com 2026-05-08
domain seylaran.com 2026-05-08
domain shadowcape.com 2026-05-08
domain swordfull.info 2026-05-08
domain velarith.com 2026-05-08
domain zarvethion.com 2026-05-08