Shuyal Stealer is a newly discovered Windows infostealer focused on credential and data theft. Reporting attributes it with stealing login credentials from 17 to 19 web browsers, including Chrome, Edge, Opera, Opera GX, Epic, Waterfox, Vivaldi, Yandex, Tor, Brave, Coc Coc, Maxthon, Chromium, Comodo, Slimjet, Falkon, 360 Browser, and others mentioned in coverage. It extracts browser credentials from browser "Login Data" SQLite databases using targeted SQL queries, and also steals Discord tokens, clipboard contents, screenshots, and browsing-related data such as history. Researchers reported stolen data being written to files including tokens.txt, clipboard.txt, ss.png, and history.txt.
The malware performs host reconnaissance using Windows Management Instrumentation commands, collecting system details such as disks, input devices, and display configuration. For exfiltration, it compresses collected data with PowerShell and sends it through the Telegram API to a hardcoded Telegram bot/chat. Coverage also states that it deletes the archive and clears traces after exfiltration, and may run a self-deletion routine via a batch script named util.bat to hinder forensic analysis.
For persistence and stealth, Shuyal Stealer copies itself into the Windows Startup folder, reportedly using CopyFileA, and has been observed disabling Windows Task Manager by terminating Task Manager processes and modifying the registry. Distribution has been reported via malicious websites and phishing emails. Point Wild's Lat61 Threat Intelligence Team is cited as the discovering/researching organization, and one report notes detection as Trojan.W64.100925.Shuyal.YR. High-confidence reporting links no specific threat actor to operation of the malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Shuyal Stealer is an information-stealing malware that targets login credentials from a wide range of web browsers, extracts clipboard text and Discord tokens, performs system reconnaissance, achieves persistence via self-replication, and exfiltrates stolen data through the Telegram API.
Information-stealing malware described as targeting 19 browsers and disabling Windows Task Manager for stealth.
Shuyal Stealer is a sophisticated infostealer malware that targets credentials and contextual data from 17 different web browsers. It profiles victim systems using WMI, collects screenshots, clipboard contents, and Discord tokens, and exfiltrates data via a hardcoded Telegram bot. It achieves persistence by copying itself to the Windows Startup folder, disables Task Manager, and deletes its traces after exfiltration to hinder forensic analysis.
Stealer malware that captures screenshots, clipboard content, and Discord tokens, exfiltrating data via Telegram bot; includes self-deletion for stealth.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.