Amnesia Stealer is a customizable open-source infostealer identified by ThreatMon on September 17, 2024 and publicly reported on October 3, 2024. It is described as operating under a Malware-as-a-Service (MaaS) model, making it accessible to cybercriminals. The malware uses Discord and Telegram for command-and-control communications.
Its stated capabilities include theft of browser passwords, Discord tokens, cryptocurrency wallet data, and Wi-Fi credentials. Reported functionality also includes keylogging, clipboard hijacking, Windows Defender bypass, and deployment of additional payloads, including trojans, cryptocurrency miners, and droppers. ThreatMon noted multiple variants, including Free and VIP editions, and reported that an Android variant was under development with intended capabilities to steal call logs, SMS messages, and WhatsApp session files.
The content places Amnesia Stealer among newly emerging stealer malware families, but does not attribute it to a specific threat actor. Associated sample filenames and SHA-256 hashes mentioned in the reporting are: s.exe (5b7e0be073dd22bd568bb9833f914c3e130863bd06d70b7623392a37d0ba4978), Build.exe (66985fe45320243565f3940f464bdab74179ac48afb9b6511e628ea826e60c33), updater.exe (bbe5544c408a6eb95dd9980c61a63c4ebc8ccbeecade4de4fae8332361e27278), crss.exe (c59a6d4e3082d0768b614b9d7e1b7a9915ee4615cea1d1bd8b45cb249a5f886c), svchost.exe (d07c47f759245d34a5b94786637c3d2424c7e3f3dea3d738d95bf4721dbf3b16), Help.Exe (dff14514b26b6278a7ffd56775c3193425e8c4ff7b544e3c3a8e2956ff9b74b8), and conhost.exe (e0338c845a876d585eceb084311e84f3becd6fa6f0851567ba2c5f00eeaf4ecf).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Amnesia Stealer is a newly emerged stealer malware family designed to exfiltrate sensitive user data.
Customizable open-source stealer malware offered as Malware-as-a-Service. It uses Discord and Telegram for C2, steals browser passwords, Discord tokens, cryptocurrency wallets, and Wi-Fi credentials, and includes keylogging, clipboard hijacking, Windows Defender bypass, and the ability to inject additional malware such as trojans, cryptocurrency miners, and droppers. An Android variant in development is described as capable of stealing call logs, SMS, and WhatsApp session files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.