Phemedrone is an open-source C# infostealer/Trojan available free to threat actors, with code distributed mainly via Telegram and previously via GitHub. It is regularly updated and customizable, which has led to multiple variants and rebrands, including a campaign where a Phemedrone variant was rebranded as “VGS.” Reporting also notes other Phemedrone variants distributed through large-scale YouTube-based malware delivery operations.
Its core capability set is credential and data theft. Phemedrone steals passwords, cookies, credit card data, and other information from Chromium-based and Firefox/Gecko-based browsers; targets numerous browser extensions including cryptocurrency wallets, password managers, and authenticator extensions; steals Discord tokens from LevelDB data; searches for cryptowallet data including wallet.dat files and hardcoded wallet targets; steals FileZilla data, Steam account files, Telegram account data, and VPN-related data from applications including OpenVPN, ProtonVPN, and SurfShark. It also includes a FileGrabber component to steal files from Desktop and My Documents, captures screenshots, and generates an Information.txt summary containing victim system information, counts of stolen data, and tag results. Unlike some stealers that only exfiltrate raw browser databases, Phemedrone parses passwords and cookies on the victim machine and tags stolen data to help operators identify valuable logs.
Observed implementation details include a GetGeoInformation() method that queries hxxp://ip-api[.]com/json/?fields=11827 for geolocation and related host metadata. Phemedrone can generate random user agents for C2 communications and supports multiple exfiltration modes: gate sender, panel sender, and Telegram sender; the Telegram sender can encrypt exfiltrated logs with AES and RSA before sending them. Anti-analysis features described in reporting include anti-debugger checks, anti-VM checks, a mutex check, and an optional CIS keyboard-language check that is disabled by default in the builder.
The malware has been observed in multiple distribution ecosystems. Reporting cited it among the most commonly used malware families in trojanized Windows Packet Divert/restriction-bypass tool campaigns affecting users in Russia, alongside NJRat, XWorm, and DCRat. Separate reporting described a pre-November 2024 campaign using YouTube videos advertising game cheats to distribute password-protected archives containing a miner and a Phemedrone variant branded as VGS, later replaced by a different stealer. Check Point also referenced other Phemedrone variants in the YouTube Ghost Network malware distribution operation.
Additional reporting states that Phemedrone has successfully bypassed Chromium App-Bound Encryption. SpyCloud telemetry cited in the content showed infections globally, with the United States accounting for 20.00% of observed logs, followed by the Netherlands at 19.00% and the Republic of Korea at 18.58%, while Russia accounted for 2.36%.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
They started distributing malware under the guise of restriction bypass programs and injecting malicious code into existing programs.
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Phemedrone will target Discord tokens by accessing the Discord leveldb database, stored on a victim’s computer. It will then regex for “dQw4w9WgXcQdQw4w9WgXcQ:[^\”]*”, which it will use to extract the victim’s Discord token for authentication purposes.
Phemedrone contains several anti-analysis checks which can be enabled during the build phase of the malware. If any of the checks described below are successful, Phemedrone exits.
Anti-VM Phemedrone’s anti-VM check checks the victim’s computer for the following virtual machine (VM) strings, which indicate that Phemedrone is being run in a VM.
Phemedrone also includes a basic filegrabber, which will iterate through My Documents and Desktop and steal all files based on config supplied max file size and directory depth.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
Stealer malware that gathers victim network and geolocation information by querying external IP-lookup services such as ip-api.com.
A named malware family (and variants) distributed through malicious YouTube videos/links in the “YouTube Ghost Network” operation; specific functionality is not described in the provided content.
Identified as one of multiple malware families reported to have successfully bypassed App-Bound Encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.