RisePro is a Windows infostealer first observed in 2022 that is used to harvest sensitive data from infected systems, including saved credentials, browser data, payment card information, and cryptocurrency wallet data. It is part of the commodity stealer ecosystem frequently discussed alongside families such as RedLine, Vidar, Lumma, and StealC, and has been implicated in credential exposure that later enabled follow-on intrusions against enterprise services.
RisePro has been distributed through multiple criminal delivery channels. Documented infection chains include cracked-software lures, malicious GitHub repositories, Discord-amplified malware distribution, and pay-per-install loader ecosystems such as PrivateLoader. In observed campaigns, loader components have injected RisePro into legitimate Windows processes to reduce detection and have delivered it alongside other malware families in multi-payload monetization chains.
On infected hosts, RisePro steals credentials and other browser-resident data and exfiltrates the collected information to operator-controlled infrastructure. It has been associated with theft of passwords, credit card data, and cryptocurrency wallet information. In some observed infections it also established persistence through scheduled tasks and startup shortcuts. Reporting also places RisePro among the infostealers whose stolen logs are traded in criminal marketplaces and later abused for credential stuffing, account takeover, and access brokerage.
RisePro has appeared in broader intrusion ecosystems affecting both consumer and corporate machines. It has been cited among the infostealers linked to exposed credentials used in Snowflake-related compromises and has also been associated with campaigns targeting users in Latin America through phishing-adjacent delivery chains and with malware hosted on GitHub and Discord infrastructure. Overall, RisePro is best understood as a commodity infostealer focused on credential and financial-data theft, commonly delivered through social-engineering-driven malware distribution and often used as an upstream enabler for subsequent criminal operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks ... (T1053.005 – Scheduled Task/Job: Scheduled Task).
Process 4192 runs a command that will start a scheduled task called “GoogleUpdateTaskMachineQC” using schtasks ... (T1053.005 – Scheduled Task/Job: Scheduled Task).
Une fois installé, il peut utiliser des techniques comme l’injection de processus pour éviter la détection et exfiltrer les données volées vers une infrastructure de commande et contrôle.
Une fois installé, il peut utiliser des techniques comme l’injection de processus pour éviter la détection et exfiltrer les données volées vers une infrastructure de commande et contrôle.
В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)
The purpose is to evade analysis environments with time-based methods, and the Windows Task Scheduler can be abused for the initial or recurring execution of malicious code (T1497.003 – Virtualization/Sandbox Evasion: Time Based Evasion, and T1053.005 – Scheduled Task/Job: Scheduled Task).
The purpose is to evade analysis environments with time-based methods, and the Windows Task Scheduler can be abused for the initial or recurring execution of malicious code (T1497.003 – Virtualization/Sandbox Evasion: Time Based Evasion, and T1053.005 – Scheduled Task/Job: Scheduled Task).
228 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family distributed by the same loader ecosystem as StealC.
Referenced only as another stealer compared against OnyxC2.
Инфостилер, для которого характерным артефактом является файл passwords.txt.
Инфостилер, упомянутый как один из вариантов, обеспечивавших поток украденных учётных данных для кампании против Snowflake.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.