SharkStealer is an information-stealing malware family associated with the use of blockchain-backed infrastructure for command-and-control support. It has been reported using the BNB Smart Chain Testnet to support info-stealing activity, specifically leveraging testnet infrastructure to reduce the effectiveness of reputation-based monitoring focused on mainnet blockchain activity. This places SharkStealer within a broader trend of malware operators adopting decentralized or blockchain-mediated mechanisms to improve resilience and complicate disruption. High-confidence reporting supports SharkStealer as a stealer rather than a ransomware or destructive actor. The available information directly ties it to theft of victim information and to the use of blockchain infrastructure as part of its operational design. No corroborated attribution to a specific nation state, criminal group, or country of origin is established in the supplied facts. Likewise, no specific victim geography, sector concentration, or broader intrusion lifecycle beyond information theft and blockchain-enabled operational support is directly established at high confidence from the available data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.