Katz Stealer is a Windows-focused Malware-as-a-Service infostealer that emerged in early 2025 and has been marketed on underground forums and messaging platforms to affiliates through subscription-based access and a web management panel. It is designed to harvest a broad range of sensitive data from infected systems, including browser credentials, cookies, session tokens, autofill data, payment information, messaging and gaming account data, email, FTP and VPN client data, Wi-Fi credentials, screenshots, clipboard contents, and cryptocurrency wallet data. Reported targeting includes browser-stored secrets, private messaging tokens, gaming platforms, and crypto assets, making it relevant to both individual and enterprise victims.
Katz Stealer has been observed in multi-stage delivery chains involving phishing and commodity loaders. Documented campaigns used archived script attachments and obfuscated JavaScript or VBS stages that launched PowerShell, retrieved steganographically concealed payloads from image files, and then executed a .NET loader commonly referred to as PhantomVAI Loader, also previously called Katz Stealer Loader or VMDetectLoader. That loader performs anti-analysis checks, establishes persistence, downloads the final payload, and injects it into legitimate processes through process hollowing, frequently using MSBuild.exe. Other reporting also describes trojanized downloads and fake software packages as delivery vectors in broader campaigns that ultimately deploy Katz Stealer.
The malware and its associated loader employ multiple evasion measures. Reported behaviors include geofencing to avoid execution on systems configured for CIS locales, virtual machine and sandbox detection, hidden PowerShell execution, and process injection into legitimate Windows processes. Some campaigns also used privilege escalation or UAC bypass techniques and scheduled-task persistence. Katz Stealer has additionally been described as launching browsers in headless mode and leveraging the browser or operating system security context to decrypt protected browser data, including bypassing some Chromium protection mechanisms such as Application-Bound Encryption in practical attacks.
Katz Stealer is associated with financially motivated cybercrime activity rather than a publicly established state nexus. It has been advertised by an operator using the handle katzadmin and has appeared as a payload in campaigns attributed to loader ecosystems such as PhantomVAI and Caminho. Observed downstream campaigns have targeted organizations across multiple sectors worldwide, including manufacturing, education, utilities, technology, healthcare, information, and government, while also affecting consumers through credential and cryptocurrency theft. Its MaaS model, modular delivery through third-party loaders, and broad data-theft scope make it a flexible commodity stealer within the 2025 crimeware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The FBI warning concerning Medusa ransomware compromising VPN credentials... One more? OK, the recent Katz Stealer warning as this threat also targeted VPN credentials.
Threat actors obfuscate these scripts in an attempt to bypass detections.
"PhantomVAI Loader Uses Steganography in Images to Inject Katz Stealer and Evade Sandboxes"
It then injects this payload into a target process that is also defined by a command-line parameter, using the process hollowing technique.
The FBI warning concerning Medusa ransomware compromising VPN credentials... One more? OK, the recent Katz Stealer warning as this threat also targeted VPN credentials.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a broader post-infostealer recovery example.
Referenced only as a comparison point for broader credential and cookie theft recovery steps.
Referenced only as a comparison family that did not technically match the observed sample.
An infostealer associated with PhantomVAI’s original marketing and delivery use case.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.