RClone-Stealer-Mega is referenced in the provided reporting as a malware/tool associated with QakBot post-takedown operations and described specifically as supporting data exfiltration. It appears in March 2026 campaign clustering and MalwareBazaar tagging alongside QuakBot/QakBot-related activity, including lures targeting Ukrainian entities. One cited sample from 2026-03-03 was tagged with UKR, Quakbot, and RClone-Stealer-Mega, and reporting on QakBot’s post-Operation Duck Hunt evolution lists association with RClone-Stealer-Mega as part of tooling expansion. The surrounding campaign activity used phishing lures themed as Ukrainian government communications, including a PDF impersonating the Bureau of Economic Security of Ukraine that redirected victims to a PixelDrain-hosted ZIP archive containing nested RAR archives, with the final payload unrecovered due to password protection. Related campaign samples used ZIP, RAR, HTML, and LNK lure formats. Based on the provided content, the high-confidence characterization of RClone-Stealer-Mega is limited to its role as a data-exfiltration-associated malware/tool linked in reporting and sample tagging to QakBot-related operations and possible overlap with the UAC-0252 cluster; specific internal functionality, persistence, supported platforms, or standalone indicators of compromise for RClone-Stealer-Mega are not directly provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MalwareBazaar pivot analysis ties this sample to a broader campaign cluster exploiting CVE-2025-8088 (WinRAR)... Second, CVE-2025-8088 (a WinRAR vulnerability) appears in three related samples from March 3-10. The password-protected RAR in our sample may be designed to exploit this same vulnerability during extraction. Without the password, we cannot confirm this -- but the pattern is suggestive.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The March 3 sample tagged UAC-0252 provides a tentative attribution anchor... 2026-03-03 27d7a398... ZIP UKR, Quakbot, RClone-Stealer-Mega Algeria-Ukraine cooperation
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a malware family in a related sample from the same broader campaign cluster; no direct payload confirmation was possible for the analyzed PDF lure because the final archive remained encrypted.
A named tool associated with QakBot operations for data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.