Muck Stealer is an information-stealing malware family observed in phishing campaigns. Cofense Intelligence documented a campaign tracked as ATR 383659 in which victims who opened what appeared to be a PDF reader unknowingly installed Muck Stealer, while a fraudulent DocuSign page opened at the same time to steal account credentials. The broader reporting states that threat actors increasingly abuse trusted developer platforms, especially GitHub and to a lesser extent GitLab, to host malicious files and support combined malware-delivery and credential-phishing operations that can evade corporate defenses. Muck Stealer was also identified as appearing almost exclusively (90%+ of observed volume) in Italian-language malware campaigns, alongside Stealerium and Teramind. Those Italian-language campaigns frequently abused legitimate URLs, especially Dropbox, and used lures themed around benefits and spoofed Italian institutions and services. High-confidence details in the provided content do not include specific technical capabilities, persistence mechanisms, or indicators of compromise for Muck Stealer beyond its classification as a stealer and its delivery via phishing-linked fake software in at least one documented case.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
When threat actors abuse github.com or githubusercontent.com, they host malware directly inside repositories or attach malicious files to comments on legitimate projects. Since github.com download links often redirect through raw.githubusercontent.com for direct file retrieval, malware can be fetched silently in the background without any visible user interaction.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware delivered via abused GitHub/GitLab links in phishing campaigns, in some cases paired with credential phishing pages.
Stealer family observed largely/exclusively in Italian-language phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.