123 Stealer is malware referenced in reporting as being linked to a Russian-speaking operator associated with Tsundere Bot. The provided content does not describe 123 Stealer’s own technical capabilities, infection vector, targeted sectors, platforms, or indicators of compromise. The only high-confidence relationship stated is that Kaspersky attributed Tsundere Bot to a Russian-speaking operator with links to 123 Stealer malware. No additional verified details about 123 Stealer are available in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential/data-stealing malware referenced as linked to the operator associated with Tsundere Bot (no additional functional details provided in the content).
Credential/data stealer referenced as linked to the operator associated with Tsundere Bot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.