WhiteSnake Stealer is a Windows information-stealing malware family sold as a malware-as-a-service offering on darknet markets. It has been used as an initial-stage payload in targeted phishing intrusions, including campaigns impersonating Russian law-enforcement investigators and distributing password-protected archives containing trojanized executables disguised as legal or tax-related documents. On infected systems, WhiteSnake Stealer collects account-related data and other sensitive information, including Wi-Fi profile configuration data and saved passwords. It can also launch an SSH proxy server on the compromised host and download or install additional malicious software, making it useful both for credential theft and as a foothold for follow-on intrusion activity. In documented intrusions, WhiteSnake Stealer has been used to deploy a second-stage backdoor that enabled broader cyberespionage actions such as persistent access, file theft, screenshot collection, and further surveillance. WhiteSnake Stealer is associated with .NET stealer codebases that share lineage with multiple forks and derivatives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
During this attack, malicious actors had sent phishing emails with an attachment containing the malicious program responsible for the initial system infection... In early October 2023, malicious actors sent several phishing emails to the email address of the affected company.
These emails were supposedly sent on behalf of an investigator with the Investigative Committee of the Russian Federation and contained two attachments. The first one was a password-protected ZIP archive. It concealed a malicious program which, when executed, initiated the system infection process.
This malware, also known as WhiteSnake Stealer, is sold on the DarkNet and is used to steal account data from a variety of software... After receiving the corresponding commands, this trojan collected and transmitted... passwords for accessing [Wi‑Fi profiles].
After receiving the corresponding commands, this trojan collected and transmitted... Wi-Fi network profiles... It then launched an SSH proxy server and installed the second stage in the system.
This malware... can download and install other malicious apps on attacked computers. In the targeted attack in question, it was assigned the role of initiating the first infection stage... It then launched an SSH proxy server and installed the second stage in the system.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the broader .NET stealer ecosystem and possible code lineage for Phantom Stealer, with similar module naming conventions and implementation patterns.
Referenced as a related .NET stealer lineage whose forks and derivatives share structural similarities with Phantom Stealer, including module naming conventions and implementation patterns.
Commercial MaaS stealer used as the initial infection stage; steals account data and other information, collected Wi‑Fi profile configuration and passwords in this incident, launched an SSH proxy server, and installed the second-stage malware.
Referenced only in the bibliography as related reading on malware analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.