Predator The Thief is a cybercriminal malware operation associated with credential-stealing activity and the development of information stealers, including Taurus. The actor has been observed marketing Taurus on criminal forums as a low-cost commodity stealer service, indicating a financially motivated crimeware model rather than state-directed activity. Predator The Thief is linked to malware designed to harvest credentials, browser-stored data, cookies, autofill information, browsing history, cryptocurrency wallet data, FTP client credentials, messaging and gaming session files, email and VPN credentials, and host profiling data. Operationally, the actor has used spam-delivered phishing documents with malicious macros for initial access. Observed infection chains used VBA macros to launch PowerShell, retrieve staged payloads, decode components with native utilities, execute AutoIt-based loaders, and inject the final stealer into a legitimate process. Taurus employed multiple anti-analysis and anti-sandbox checks, including timing-based evasion, host artifact checks, computer-name checks, and connectivity tests, then assembled exfiltration data in memory and transmitted it to command-and-control infrastructure using runtime-built configuration data. Predator The Thief infrastructure has also been associated with a distinctive static HTTP response on command-and-control servers, enabling infrastructure clustering through HTTP fingerprinting. Known activity indicates a broad cybercrime focus on credential theft, session theft, host reconnaissance, defense evasion, and data exfiltration. No high-confidence evidence in the available facts supports attribution to a specific country or a narrowly defined victim geography.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developing and selling the Taurus stealer, a credential- and information-stealing malware distributed via spam emails with malicious macro documents, using PowerShell, AutoIt, anti-sandbox checks, process injection into dllhost.exe, and exfiltration of stolen data to C2 infrastructure.
Stealer malware whose command-and-control servers can be identified via a static HTTP response fingerprint.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.