Katz Stealer is an infostealer offered as a Malware-as-a-Service operation that emerged in early 2025 and gained adoption among cybercriminals through accessible distribution and customizable features. It is designed to steal a broad range of sensitive information from compromised systems, including data from web browsers, messaging applications, gaming services, email clients, VPN software, and cryptocurrency wallets. The malware is associated with multi-stage intrusion chains that commonly begin with phishing or trojanized software downloads. Reported execution and post-compromise behavior includes JavaScript-based droppers, PowerShell execution, user account control bypass, process hollowing, abuse of legitimate processes for concealment, and scheduled-task persistence. It has also been observed extracting browser decryption material and decrypting protected data in memory to defeat browser data protections such as Google Application Bound Encryption. Stolen information is exfiltrated to command-and-control infrastructure over HTTP, and the malware includes functionality to remove traces from infected hosts. Katz Stealer is best characterized as a financially motivated cybercriminal toolset focused on credential and data theft rather than ransomware or destructive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.