Stealerium is an open-source .NET/C# information stealer first noted in 2022 and publicly available on GitHub, where it was described as a stealer, clipper, and keylogger. It is widely referenced as an infostealer family and as the codebase underlying later forks and variants, including Phantom Stealer/PhantomStealer, with multiple reports noting significant code overlap and family lineage.
High-confidence capabilities described in the source material include theft of browser credentials, browser cookies, session tokens, cryptocurrency wallet data, and general sensitive information from compromised Windows systems. Stealerium can exfiltrate stolen data through multiple channels, especially Discord webhooks, and reporting also associates the broader family with SMTP, Telegram, FTP, and other exfiltration paths in derived variants. The malware also includes clipper functionality to replace copied cryptocurrency wallet addresses and keylogging functionality.
A notable feature documented by Proofpoint is NSFW-triggered surveillance behavior: Stealerium can be configured to monitor open browser tabs for keywords such as "sex" or "porn" and, when triggered, capture a desktop screenshot and a webcam image. Reporting states newer modules were added specifically to support sextortion-style abuse and blackmail.
Stealerium has been delivered in phishing and social-engineering campaigns, including ClickFix-style chains and campaigns using malicious SVG files to trigger PowerShell execution. It has also appeared in multilingual phishing activity, including Italian-language campaigns. The malware has been observed or reported in campaigns targeting enterprise victims and sectors including logistics, industrial, manufacturing, technology, retail, construction, and IT, though some of those campaigns involved Stealerium-derived Phantom variants rather than base Stealerium itself.
The content also notes operational abuse of Discord infrastructure: Stealerium has used Discord webhooks to steal credentials, browser cookies, and cryptocurrency wallets, and broader reporting cited it among malware families abusing Discord services for delivery or exfiltration.
Relevant high-confidence indicators and associations mentioned in the content include the GitHub handle "witchfindertr" as the public developer identity for the released codebase, Discord webhook-based exfiltration, and strong code/family overlap with Phantom Stealer/PhantomStealer. The content does not provide a canonical malware hash for base Stealerium itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
... delivering an open-source information stealer called Stealerium (or variants of it).
... delivering an open-source information stealer called Stealerium (or variants of it).
11 distinct techniques documented for this family, organized by ATT&CK tactic.
This campaign is a textbook example... combining open-source code (Stealerium base), deep obfuscation, and skilled loader engineering... pushing the boundary of what’s possible with “just scripts”
"trick users into executing PowerShell commands that deploy the StealC information stealer"; "instruct the victim to run a PowerShell command ... resulting in ... Stealerium"
The script’s surface was a tangled web of Chr() arithmetic, farm-themed variable names, and aggressive string concatenation... Junk strings replace executable commands... split into multiple fragments and littered with “mango”/“avocadopapaya” to defeat automated forensics.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
According to Trellix's data, various malware families, including Agent Tesla, UmbralStealer, Stealerium, and zgRAT, have also used Discord webhooks over the past few years to steal sensitive information like credentials, browser cookies, and cryptocurrency wallets from compromised devices.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source .NET infostealer project that served as the codebase/foundation for Phantom Stealer. It appears to be a simpler precursor without the larger embedded SQLite and BouncyCastle components described for Phantom Stealer.
Referenced as the malware family lineage from which PhantomStealer derives. It provides a modular collector-plus-exfiltration architecture inherited by PhantomStealer.
Commodity stealer used alongside Infy’s proprietary malware.
Open-source .NET infostealer delivered after a ClickFix flow initiated by phishing with a malicious SVG inside a password-protected ZIP, leading the victim to run a PowerShell command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.