MonsterV2 is a subscription-based malware-as-a-service family advertised on cybercriminal forums since at least February 2025 and also referred to as Aurotun Stealer. It is consistently described as a multifunctional remote access trojan (RAT), stealer, loader, and backdoor. Reported capabilities include theft of browser credentials, login data, credit card data, cryptocurrency wallet data, Steam/Telegram/Discord tokens, files and documents; command execution; downloading and executing additional payloads; desktop viewing; webcam recording; clipboard cryptocurrency address replacement (clipper); and hidden remote desktop control via HVNC. Proofpoint also reported MonsterV2 loading additional malware including StealC V2 and Remcos. The malware avoids infecting systems in Commonwealth of Independent States (CIS) countries. Technical details directly mentioned in the content include use of api.ipify[.]org prior to or during C2 setup to obtain external IP/geolocation information, ChaCha20/ZLib-based configuration and C2 communications, and frequent packing with the SonicCrypt crypter, which adds anti-analysis checks and can execute decrypted payloads via Windows Task Scheduler COM. MonsterV2 has been associated primarily with TA585, which frequently delivers it through ClickFix-style social engineering, compromised websites with malicious JavaScript fake CAPTCHA overlays, phishing campaigns including IRS- and SBA-themed lures, and abused GitHub notification emails that drive victims to attacker-controlled ClickFix pages. It has also been observed distributed via CastleLoader/CastleBot infrastructure linked to TAG-150/GrayBravo, alongside other stealers and RATs. Targeting noted in the content includes finance and accounting firms in some phishing campaigns, while broader delivery activity appears global. Mentioned indicators and infrastructure artifacts include the domain intlspring[.]com used in TA585 web-inject infrastructure and api.ipify[.]org as a network observable used by the malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The main malware payload used by TA585 is MonsterV2, a backdoor, stealer and loader MaaS.
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an infostealer family distributed by CastleLoader.
MonsterV2 is a malware family distributed via the CastleLoader framework.
Subscription-based MaaS malware family advertised in Feb 2025. Delivered via ClickFix social engineering (victim copy/pastes PowerShell), then installs to steal credentials/tokens/crypto wallet data and provides hidden remote control via HVNC.
Multi-capability malware sold on criminal forums and delivered by TA585; functions as a RAT/loader/stealer and includes geofencing to avoid CIS infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.