Lone None Stealer is an information-stealing malware family associated with the Vietnamese hacking group Lone None. It has been observed in an online scam and phishing campaign active since at least November 2024, including fake legal takedown emails purportedly from law firms and phishing lures related to U.S. Social Security Administration and copyright infringement. The campaign distributes malware through links to archive files such as ZIPs, with payloads disguised as evidence documents including PDFs or PNGs, and uses DLL side-loading to execute the malware and bypass security checks. Lone None Stealer is also referred to in the reporting as PXA Stealer. Its primary focus is cryptocurrency theft: it monitors the victim’s clipboard and, when a cryptocurrency wallet address is copied, replaces it with an attacker-controlled address. Reporting also states that the broader campaign targets personal and financial information, uses Telegram bot profile pages as a staging mechanism, and relies on the Telegram network as the primary command-and-control channel, with stolen data rapidly exfiltrated via Telegram. The use of roughly ten languages, including English, French, German, and Chinese, indicates broad global targeting. Cofense reported increased use of Lone None Stealer from June 2025 onward, noting it appeared in 29% of recent reports involving Pure Logs Stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer malware designed to exfiltrate sensitive data from infected systems.
Information stealer malware focused on stealing cryptocurrency by monitoring clipboard activity and replacing copied wallet addresses with the attacker's address. Uses Telegram as its primary C2 channel and employs DLL side-loading for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.