Phemedrone Stealer is a .NET/C# information-stealing malware family focused on covert collection and exfiltration of sensitive user data from Windows systems. Reported theft targets include browser data and credentials from Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, Discord tokens and sessions, Telegram sessions, Steam accounts and sessions, screenshots, personal details, and financial information. The malware has been described as gathering data in memory, using no external libraries, supporting both x86 and x64 systems, and exfiltrating to an HTTP host. It is also reported to include anti-CIS, anti-VM, anti-debug, and other security-evasion capabilities, and content further states it can leverage command-and-control infrastructure, facilitate remote access, and exploit vulnerabilities.
A documented 2026 campaign used a compromised WordPress site, acbcr[.]ro, to deliver Phemedrone to Hungarian-speaking victims via a JavaScript lure named Rendelés_aqualing_2026_22445146200001.js. That chain downloaded an AES-256-CBC encrypted PowerShell payload from hxxps://acbcr[.]ro/wp-content/update.ps1, which after decryption revealed an XOR-protected .NET assembly, ALTERNATE.dll. ALTERNATE.dll was obfuscated with CryptoObfuscator, used namespace ALTERNATE, class ALTERNATE.EXECUTE, entry method LAUNCH, and performed process hollowing into aspnet_compiler.exe to launch the final Phemedrone payload disguised as svchost.exe. In that case, the final Phemedrone sample had SHA256 c916f289ff9a05d74d72f28582ff03690d415fe64a4195b4f47195fe286c6d2d, was approximately 750 KB, packed with Costura/Fody, and contained an embedded shellcode handle labeled ~draGon~. The associated loader ALTERNATE.dll had SHA256 c8a0077a21f2ba22ec5a6d956b012b794c8b5a70e5ccd05adcff786020850791, and the encrypted PowerShell payload update.ps1 had SHA256 c023166a028773efc229e5d4a052fd768d356f7674bc57de91169b9c47bcae55. The AES key and IV observed in the JavaScript dropper were wgJ/fzXmOQvFo6Edg9U0SoQr6rEdvegLcUT35OSmDQ0= and YzVJsAmkpoAPJnVvW5n1dA==, and the XOR key embedded in the decrypted PowerShell was vkSecretKey765.
The same campaign linked to a separate Formbook operation through an identical PDB path in ALTERNATE.dll, C:\Users\VICTOR\Documents\CryptoObfuscator_Output\ALTERNATE.pdb, suggesting a shared developer or loader-as-a-service provider identified by the username VICTOR. Phemedrone has also been associated with exploitation of CVE-2023-36025 for defense evasion and distribution. Additional reporting ties the malware to broad criminal distribution ecosystems, including the YouTube Ghost Network, which used compromised YouTube accounts and videos promoting pirated software and cheats to distribute multiple stealers including Phemedrone Stealer. Dark web forum reporting described Phemedrone as open-source C# malware with full source code and an "educational purposes" disclaimer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Phemedrone Stealer is a potent data-stealing malware designed to infiltrate systems discreetly, primarily targeting sensitive user information. | Leveraging the CVE-2023-36025 vulnerability for defense evasion, this malware exhibits a relentless pursuit of sensitive data.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Property Value ... Packer Costura/Fody (embedded dependency bundler) ... MITRE ATT&CK Mapping ... T1027.002 Costura/Fody packing
MITRE ATT&CK Mapping ... Defense Evasion Obfuscated Files or Information: Encrypted/Encoded File T1027.013 AES-256-CBC + XOR layered encryption
MITRE ATT&CK Mapping ... Defense Evasion Masquerading: Match Legitimate Name T1036.005 Phemedrone disguised as svchost.exe
ALTERNATE.dll's sole function is process hollowing: it spawns a suspended instance of aspnet_compiler.exe ... hollows out its memory, injects the final payload, and resumes execution.
Leveraging the CVE-2023-36025 vulnerability for defense evasion...
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET information stealer that targets browser credentials, cryptocurrency wallets, Discord tokens, Telegram sessions, and Steam accounts. In this campaign it is disguised as svchost.exe and delivered via a multi-stage chain using encrypted PowerShell and the ALTERNATE.dll injector.
Associated Analytic Story ... Phemedrone Stealer ...
Associated Analytic Story ... Phemedrone Stealer
Associated Analytic Story Active Directory Lateral Movement ... NOBELIUM Group ... Phemedrone Stealer ... Prestige Ransomware ... Quasar RAT ... RedLine Stealer ... Scheduled Tasks
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.