Agniane Stealer is a Windows information-stealing malware family focused on harvesting credentials, browser data, application session material, host profiling information, selected user files, and cryptocurrency-related data. It has been observed on both 32-bit and 64-bit Windows systems and uses dynamically retrieved SQLite-related components to access browser and application databases.
The malware targets login data, browsing history, web data, and cookies from multiple browsers including Chromium- and Gecko-based products. It also steals session data from applications such as Telegram, Discord, Steam, OpenVPN, WinSCP, and FileZilla. For Telegram collection, it attempts to terminate the client before copying session-related files. It includes form-grabbing functionality and has been reported to extract credentials associated with selected online services. In addition, it supports theft of cryptocurrency wallet and extension data and exhibits clipper-style cryptocurrency theft behavior.
Agniane Stealer performs extensive victim profiling before exfiltration. Observed functionality includes collecting the external IP address, Windows version, CPU, GPU, RAM, installed antivirus products, and installed applications, as well as capturing desktop screenshots. It also searches user-accessible locations such as Desktop and Documents for selected document, database, remote access, and cryptocurrency-related file types, stages the collected material in a temporary working directory, uploads the stolen data to remote infrastructure, and then deletes the temporary folder to reduce forensic traces.
Recent variants have used stronger obfuscation, including ConfuserEx Protector, compared with earlier builds. The malware has been linked in reporting to the same developer or lineage associated with Xehook Stealer, which has been assessed as a later and more heavily developed iteration sharing code and operational similarities with Agniane Stealer. The family is associated with credential theft, session theft, cryptocurrency-focused theft, host reconnaissance, and anti-forensic cleanup on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Uses WMI to collect Installed Antiviruses: Collects all installed antivirus software with the WMI query Select * from AntivirusProduct. GPUName: Using WMI query SELECT * FROM Win32_VideoController... CPU name: Using WMI query SELECT * FROM Win32_Processor... Checks RAM By querying WMI to Select * From Win32_ComputerSystem
the latest version of the Agniane Stealer uses ConfuserEx Protector. Also, the recent variant employs more obfuscation techniques when compared to the earlier version
Agniane Stealer targets login data, history, and web data from the following browsers: OperaGX Chrome Opera FireFox Vivaldi Brave Edge Yandex Chromium
Agniane Stealer tries to harvest login credentials and cookies from following domains: VK.com facebook.com instagram.com mail.ru | Agniane Stealer pilfers WinSCP to collect Hostname, username, and password from all sessions by traversing through Software\Martin Prikryl\WinSCP 2\Sessions registry entry. Agniane Stealer reads FileZilla\recentservers.xml and searches for the tag. If available, then Agniane Stealer grabs Hostname, username, and password.
Agniane Stealer pilfers WinSCP to collect Hostname, username, and password from all sessions by traversing through Software\Martin Prikryl\WinSCP 2\Sessions registry entry.
Agniane Stealer gets the external IP address of the victim's machine... collects victims Windows version... obtains the bit version of the machine... Collects all installed antivirus software... CPU name... Checks RAM... collects all applications installed on the victim’s machine
Agniane Stealer enumerates the users Desktop and the Documents folder for the files with .txt,.doc,.mafile,.rdp, and .db extension. The discovered files are then copied to the previously created subfolder under the %TEMP% location.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware that harvests browser credentials, cookies, Telegram and Steam session data, OpenVPN profiles, WinSCP and FileZilla credentials, system information, screenshots, installed applications, selected files from Desktop/Documents, and cryptocurrency wallet/extension data, then uploads the stolen data to a remote C2 server and deletes local traces.
A stealer malware family presented as a predecessor or earlier iteration of Xehook, with overlapping code, similar configuration structure, shared Telegram handle references, and communication with the same C2 server.
A stealer malware noted as similar to Xehook Stealer and apparently written by the same author.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.