Rublevka Drainer is a custom JavaScript-based cryptocurrency wallet drainer used by Rublevka Team, an affiliate-driven cryptoscam operation active since 2023 and operating primarily via LolzTeam Forum, with additional presence on Exploit and XSS. In 2024, the group shifted from fake exchanges and TON-themed lures to deploying this drainer on phishing and impersonation landing pages, and later focused heavily on Solana campaigns in 2025. The malware is embedded in landing pages as an obfuscated JavaScript file, notably index.js (SHA-256: 9c21d538c2a556f4a5b351b29f3513097ac57643f291ff6d751400d8dbc69489), assessed as possibly obfuscated with js-confuser. Its purpose is to trick victims into connecting Solana-compatible wallets and signing transactions that transfer assets to attacker-controlled addresses.
The drainer was advertised as supporting more than 90 wallet types and the theft of SOL, SPL tokens including SPL2022, NFTs, and Native Stake. Rublevka Team documentation and reporting indicate support for wallets including Solflare, Phantom, Backpack, Coinbase, Bitget, OKX, and MetaMask. The malware includes wallet-specific social engineering modes for Phantom, including Honeypot, Honeypot2, Fake Return, Crasher, Whitelist, Warning, and Remove Phantom. The JavaScript also exposes an API referred to as PiterAPI, stored in the variable piter, with functions including connect, process, onConnect, getBalance, getAddress, and setToken, enabling further customization by affiliates.
Rublevka Team distributed the drainer through a Telegram-based affiliate ecosystem that included a bot, landing-page generator, hosting/domain options, cloaking, white pages for evasion, CAPTCHA via Cloudflare, redirect logic, and Telegram notifications for visits and withdrawal requests. The bot also supported Autosplit functionality to send stolen funds directly to affiliate wallets. Landing pages impersonated brands and services including Axiom, Bitget, Photon, Jito, and Marinade, and spoofed token airdrops for Bonk, DogWifHat, Trump, Pengu, and Fartcoin.
Observed infrastructure and network indicators associated with the drainer include mainnet[.]helius-rpc[.]com with multiple API keys, rpc[.]walletconnect[.]org with projectId 730eede4c040eafa7a928a503b6cd650, solana-rpc[.]publicnode[.]com, and wallet-api[.]solflare[.]com. Shared domains attributed to the operation include open-sol[.]cc, sol-galaxy[.]cc, web-core[.]cc, sol-hook[.]org, and sol-coin[.]xyz. Insikt Group also reported approximately 160 strings resembling Solana addresses in the drainer code, with roughly 130 assessed as likely attacker-linked. The operation used Cloudflare fronting, domain rotation, and apparent DGA-like subdomain patterns for evasion. As of October 2025, 50 unique drainer landing pages and 11 white landing pages were identified in Rublevka Team’s catalog.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"In 2024, however, Rublevka Team fundamentally shifted its tactics to deploy a custom JavaScript-based cryptocurrency wallet drainer on its landing pages..."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obfuscated JavaScript wallet-drainer embedded in phishing/impersonation landing pages that prompts victims to connect Solana-compatible wallets and sign transactions, then enumerates holdings and drains SOL, SPL tokens (including SPL-2022), NFTs, and stake. Includes multiple Phantom-specific social-engineering modes (e.g., Honeypot/Honeypot2/Fake Return/Crasher/Warning/Whitelist), Telegram WebApp integration, cloaking/"white page" bypass features, and uses Solana RPC providers (Helius/PublicNode) and WalletConnect to facilitate malicious transactions.
A custom, heavily obfuscated JavaScript wallet-drainer embedded in phishing/impersonation landing pages. It enumerates Solana wallet holdings and tricks victims into signing malicious transactions to transfer SOL, SPL tokens (including SPL-2022), NFTs, and stake assets to attacker-controlled addresses. It supports many wallet types and includes Phantom-specific social-engineering modes (e.g., Honeypot, Crasher, Fake Return), Telegram Mini App integration, cloaking/"white page" bypass features, and an exposed customization interface referred to as PiterAPI.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.