Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“More than 20 Umbral Stealer reports were uploaded to these channels via webhooks between January 7 – 9, 2024, including those that Sty1x sent to Fucos.”
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The file named “wime.exe” is a 32-bit binary packed using the Themida packer. When executed, the file unpacks itself and loads the Umbral Stealer into the process memory.
The NSIS installer file “Super-Mario-Bros.exe” has been tampered with and turned into a trojanized version of a Super Mario game installer.
the malware gathers valuable data from the victim’s system, including computer name, username, GPU, CPU, and other relevant details.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly available stealer mentioned as a comparison for the analyzed specimen’s design and obfuscation techniques. The report suggests possible common authorship but provides no evidence that Umbral-Stealer was deployed in this execution or used as an additional payload.
Open-source information stealer whose stolen-data reports were uploaded through Discord webhooks. Researchers found more than 20 reports in channels accessible to Sty1x and another user, and identified reports Sty1x forwarded to Fucosreal. The evidence suggests Sty1x either operated Umbral Stealer or participated in a group using it; direct operation was not established conclusively.
A Windows-based open-source C# information stealer that exfiltrates data via Discord webhooks. It performs anti-VM checks, may request elevation, attempts to evade or disable Defender, can add itself to startup, blocks antivirus-related websites, and steals browser credentials, cookies, webcam images, Telegram sessions, Discord tokens, Roblox cookies, Minecraft sessions, and cryptocurrency wallet files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.