NeedleStealer is a malware framework associated with cryptocurrency-focused intrusion activity on Windows. Public reporting describes multiple NeedleStealer components implemented in Rust, Go, and Golang, indicating that the name is used for more than one payload within a broader toolkit rather than a single monolithic binary. Observed functionality centers on theft of browser credentials and sessions, cryptocurrency wallet data, Telegram data, screenshots, and in some campaigns browser-extension-based collection of authenticated session material. In separate reporting, NeedleStealer has also included a wallet-spoofing component that imitates desktop cryptocurrency wallet software to socially engineer victims into disclosing recovery seed phrases, and a browser-extension installer that deploys malicious extensions masquerading as legitimate software to harvest credentials and active sessions.
NeedleStealer has been observed in targeted social-engineering campaigns against cryptocurrency users and organizations, including fake Web3 recruitment and interview lures that culminate in delivery through signed ClickOnce applications on Windows. In those intrusions, NeedleStealer was deployed alongside additional malware such as a separate Rust infostealer and a Go remote-access trojan with hidden VNC capability, contributing to compromise of private keys and rapid theft of digital assets. NeedleStealer has also been linked to CastleLoader-related campaigns in which fake installers, fake updates, and ClickFix-style prompts lead to staged delivery of cryptocurrency-focused payloads.
Across reported variants, NeedleStealer targets browsers, wallet extensions, desktop wallets, and messaging artifacts relevant to cryptocurrency operations. Its role in these campaigns is consistent with information theft and session theft, with some components also using spoofed wallet interfaces or malicious browser extensions to obtain wallet recovery material and persistent browser access. Reporting links NeedleStealer to broader criminal ecosystems overlapping with GAPI_Update and CastleLoader activity, but currently available evidence does not conclusively establish a single operator or definitive state attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The sheet was a Google Apps Script web app. The Windows delivery was a signed Microsoft ClickOnce application named GapiUpdate.application.
The stager opened a legitimate-looking Google Workspace page in WebView2, requested configuration from attacker infrastructure, downloaded a password-protected archive named Razo.rar , and unpacked three executable payload wrappers...
Instead of a harmless document, the assessment sent the target toward a signed Microsoft ClickOnce application, a Windows deployment format seen as trustworthy.
The “assessment” was instead a malicious Google Apps Script web app masquerading as a Workspace document.
The archive contained three files disguised as PNG images, but each began with a Windows MZ executable header.
Instead of a harmless document, the assessment sent the target toward a signed Microsoft ClickOnce application, a Windows deployment format seen as trustworthy.
ClickOnce can look less suspicious than a bare executable because Windows launches it through trusted components such as dfsvc.exe.
NeedleStealer targeted browser credentials, sessions, wallet extensions, Telegram data, and screenshots.
NeedleStealer targeted browser credentials... The Rust stealer broadened the collection scope to browsers, desktop wallets, password managers
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer used in a related campaign to steal browser credentials and sessions, wallet extensions, Telegram data, and screenshots.
A stealer payload delivered by the malicious ClickOnce chain; the content indicates it was staged after execution of GapiUpdate.application and contributed to credential, wallet, browser-session, and other data theft.
Named malware referenced in connection with a phishing campaign and a multi-payload Windows infection chain involving signed ClickOnce delivery.
An infostealer used in the campaign to collect browser credentials, sessions, wallet extension data, Telegram data, and screenshots.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.