Predator The Thief is a Windows information-stealing malware family sold in underground markets with an associated builder and command-and-control panel. Active since at least 2018, it is designed to harvest sensitive data from infected systems, including browser-stored passwords and other browser data, payment-related information, Steam data, cryptocurrency wallet information, host details, screenshots, and webcam images. Some observed variants also implement clipboard replacement for cryptocurrency theft.
The malware has been distributed through multiple crimeware channels, including phishing campaigns using fake documents, fake PDFs, ZIP archives, and exploitation of CVE-2018-20250 in WinRAR, as well as fake software-update and malvertising chains, cracked-software bundles, and secondary delivery by other malware ecosystems. It has appeared as an initial payload in FakeUpdates/SocGholish campaigns and has also been delivered through broader malware distribution operations such as Phorpiex and Bitbucket-hosted cracked-software campaigns.
Observed samples used packing and obfuscation to hinder analysis, including AutoIt-based wrapping, string obfuscation, anti-debugging and anti-sandbox options, and trap routines intended to mislead reverse engineers. In one documented execution chain, an AutoIt loader decoded shellcode and injected Predator The Thief into a hollowed legitimate process. Configuration-controlled features have included screenshot capture, webcam capture, Firefox credential theft, and other stealer functions. Underground advertising around later versions claimed fileless operation, but such claims were not broadly confirmed in the wild.
Predator The Thief is associated with Russian-speaking cybercrime activity and has been linked in reporting to aliases used by its developer or seller in underground forums and Telegram channels. It is commonly discussed alongside commodity stealers such as AZORult, RedLine, Raccoon, Ficker, and Taurus Stealer, and Taurus has been noted to share substantial similarities in configuration handling, obfuscation, functionality, and execution flow. Predator The Thief remains notable as a commodity infostealer used both as a standalone credential-harvesting tool and as part of larger intrusion chains that can progress to additional payload delivery, including ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Another sample exploits a vulnerability in the UNACEV2.dll library of WinRAR software previously identified in CVE-2018-20250. When the victim decompresses the malicious '.rar' file, three dummy '.png' images are shown. However, in the background, the exploit is triggered and a malicious file called 'hi.exe' is placed in Windows Startup folder. | In March 2019, FortiGuard Labs discovered a running campaign against Russian-speakers using a new version of “Predator the Thief” stealer malware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransomware operators are using malicious fake ads for Microsoft Teams updates to infect systems with backdoors... Planting the malicious fake ads that lure unsuspecting users into clicking it to install an update was possible by poisoning search engine results or through malicious online advertisements.
Microsoft recommends using strong, random passwords for local administrators... Once attackers have valid credentials, only 37% of their actions are blocked.
Removable device file replacement It creates files with a “*.pif” extension, copies the names from the original files, and then removes the original files. It replaces all the files on removable devices with the malware and tries to deceive its victims into executing the malware.
Clicking on the link downloaded a payload that executed a PowerShell script to retrieve more malicious content.
The same actor was using one set of dummy files to deliver the stealer via different forms of phishing, including Zipped files, fake documents, fake pdfs, and the WinRAR exploit described in CVE-2018-20250.
Another sample exploits a vulnerability in the UNACEV2.dll library of WinRAR software previously identified in CVE-2018-20250.
As the de-obfuscated script shows, it reads and decodes the resource, then it loads the shellcode for injecting the decoded payload — which is Predator the Thief malware.
When AutoIt script calls the shellcode, it creates a suspended process for “dllhost.exe”, and then uses this hollow process to inject the Predator payload.
Microsoft recommends using strong, random passwords for local administrators... Once attackers have valid credentials, only 37% of their actions are blocked.
When the victim decompresses the malicious “.rar” file, three dummy “.png” images are shown. However, in the background, the exploit is triggered and a malicious file called “hi.exe” is placed in Windows Startup folder.
The code of the malware is obfuscated to try and slow down any analysis. We found that every string in Predator is dynamically produced, with some of them being hardcoded in the file or its assembly with simple byte operations like “xor”, “not” or “sub” encoding.
it uses a document-like icon to fake the document with an executable file.
As the de-obfuscated script shows, it reads and decodes the resource, then it loads the shellcode for injecting the decoded payload — which is Predator the Thief malware.
When AutoIt script calls the shellcode, it creates a suspended process for “dllhost.exe”, and then uses this hollow process to inject the Predator payload.
Microsoft recommends using strong, random passwords for local administrators... Once attackers have valid credentials, only 37% of their actions are blocked.
The meanings for different items are shown below. p2: Anti-debug/Anti-sandbox
It can gather information about an infected host, steal passwords from browsers, replace cryptocurrency wallets in the buffer, take photos from the web-camera, and many other configurable options.
Azorult scans the file system and searches for sensitive data like browser data, cookies... Vidar is a well-known information stealer that collects system information, passwords from browsers... Predator is an information stealer that steals credentials from browsers.
Removable device file replacement It creates files with a “*.pif” extension, copies the names from the original files, and then removes the original files. It replaces all the files on removable devices with the malware and tries to deceive its victims into executing the malware.
It can gather information about an infected host, steal passwords from browsers, replace cryptocurrency wallets in the buffer, take photos from the web-camera, and many other configurable options.
The meanings for different items are shown below. p5: Screenshot capture
It can gather information about an infected host, steal passwords from browsers, replace cryptocurrency wallets in the buffer, take photos from the web-camera, and many other configurable options.
When we did spot IRC C&C servers online, we managed to capture a command for loading another malware to the infected machines... Tldr is a downloader that uses HTTP protocol for communication with C&C servers. Its main purpose is to load another malware on the infected machines.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer used as an initial payload and downloader in the campaign; steals browser credentials, screenshots, webcam images, and cryptocurrency wallets, and retrieves additional malware from Bitbucket.
Referenced in the article's references as another named stealer malware, but no substantive discussion is provided in the main content.
Information-stealing malware referenced as highly similar to Taurus Stealer in configuration loading, obfuscation, functionality, and execution flow.
Mentioned as one of several malware families that may be included in an alternate malware bundle delivered via the same traffic direction system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.