Phemedrone is a free, open-source C# information stealer targeting Windows systems. Its source code has been distributed through Telegram and was formerly available through GitHub, enabling operators to customize builds, exfiltration settings, and optional anti-analysis controls. Phemedrone has been used directly and as the basis for renamed or related variants, including Mephedrone and a variant branded VGS.
Phemedrone steals browser passwords, payment-card data, cookies, and other browser artifacts from Chromium- and Gecko-based browsers. It targets browser extensions and local application data associated with cryptocurrency wallets, password managers, authenticators, Discord, FileZilla, Steam, Telegram, and VPN clients. It can collect cryptocurrency-wallet files, Discord tokens, selected user documents, screenshots, and host, hardware, public-IP, and geolocation information. The malware processes and tags harvested credentials and cookies locally to identify data associated with predefined services, including Russian financial and online-service targets.
The stealer supports gate, panel, and Telegram-based exfiltration; Telegram delivery of collected logs can be protected with AES and RSA encryption. It includes anti-debugging, anti-virtual-machine, mutex, and optional CIS keyboard-layout checks. Phemedrone previously exploited the Windows SmartScreen bypass vulnerability CVE-2023-36025. Later versions added theft of Chrome cookies protected by Application-Bound Encryption by launching Chrome with remote debugging enabled and retrieving plaintext cookies through the Chrome DevTools interface. Phemedrone has also been distributed in malicious software and game-cheat lures, including YouTube-hosted campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PHEMEDRONE caught the world's attention earlier in the year through its usage of a Windows SmartScreen vulnerability (CVE-2023-36025). | This open-source stealer caught the world's attention earlier in the year through its usage of a Windows SmartScreen vulnerability (CVE-2023-36025).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
They started distributing malware under the guise of restriction bypass programs and injecting malicious code into existing programs.
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Phemedrone will target Discord tokens by accessing the Discord leveldb database, stored on a victim’s computer. It will then regex for “dQw4w9WgXcQdQw4w9WgXcQ:[^\”]*”, which it will use to extract the victim’s Discord token for authentication purposes.
Infostealers implement bypasses around Chrome Application-Bound Encryption to retrieve cookie data; STEALC, METASTEALER, PHEMEDRONE, XENOSTEALER, and LUMMA recover cookies in plaintext.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
PHEMEDRONE performs a browser check for Chrome versions greater than or equal to 127. STEALC selects CookieMonster signature patterns based on the installed Chrome version.
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Anti-VM Phemedrone’s anti-VM check checks the victim’s computer for the following virtual machine (VM) strings, which indicate that Phemedrone is being run in a VM.
Phemedrone also includes a basic filegrabber, which will iterate through My Documents and Desktop and steal all files based on config supplied max file size and directory depth.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
Stealer malware that gathers victim network and geolocation information by querying external IP-lookup services such as ip-api.com.
A named malware family (and variants) distributed through malicious YouTube videos/links in the “YouTube Ghost Network” operation; specific functionality is not described in the provided content.
Named information-stealing malware listed as detectable via favicon hash hunting of exposed infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.