LeakyStealer is a malware family reported alongside LeakyInjector and used in attacks against cryptocurrency owners. Based on the provided reporting, it targets cryptocurrency wallets and browser history. It implements a polymorphic engine that modifies memory bytes using specific hard-coded values at runtime. It also beacons to an external server at regular intervals, from which it can execute Windows commands and download and run additional payloads. The available content associates it with attacks against crypto-focused victims, but does not attribute it to a specific threat actor or provide concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LeakyStealer is a stealer malware that targets cryptocurrency wallets and browser history, using polymorphic techniques to evade detection and regularly communicates with a C2 server for further instructions.
LeakyStealer is an information stealer malware targeting cryptocurrency owners, designed to exfiltrate sensitive data such as wallet credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.