Cyber Stealer is a stealer malware family first identified by eSentire's Threat Response Unit (TRU) in May 2025. The available reporting describes it as a new, feature-rich stealer with command-and-control communications that include heartbeat checks, task checks, XMR miner configuration, and data exfiltration. Based on the provided content, its core functionality is credential and data theft, and it may also support cryptocurrency mining-related configuration via its C2 channel. No specific infection vector, malware author, or attributed threat actor is identified in the supplied material. No specific targeted industries, operating systems, or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer with credential theft, system reconnaissance, clipper, remote shell, reverse proxy, DDoS, XMR mining, and DNS poisoning capabilities.
Cyber Stealer is a newly identified stealer malware, first discovered in May 2025, designed to harvest sensitive information from infected systems.
Cyber Stealer is a newly identified stealer malware, first discovered in May 2025, designed to harvest sensitive information from infected systems.
Cyber Stealer is a newly identified stealer malware, first discovered in May 2025, designed to harvest sensitive information from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.