StressPaint is a Windows information-stealing trojan focused on harvesting browser-stored credentials and session cookies, particularly for Facebook account abuse. It has been observed hidden inside a trojanized drawing application presented as a legitimate stress-relief painting tool, allowing the visible program to function while malicious components execute in the background. Distribution has been associated with spam-driven promotion, including social-media and email lures, and the malware has been linked by multiple researchers to a broader Chinese-language cybercriminal ecosystem involved in social-platform monetization and ad-fraud operations alongside families such as SilentFade, CopperStealer, FacebookRobot, and Scranos.
On infected systems, StressPaint establishes persistence on Windows and generates a per-victim identifier. It targets Chromium browser data by copying browser credential and cookie databases and querying the copied files rather than the originals, a technique that can reduce contention with locked browser files and may help evade some security monitoring. It steals saved Chrome login data and session cookies, encrypts the collected information, and uploads it to remote command-and-control infrastructure. Observed operator activity indicates a strong emphasis on Facebook account takeover: stolen credentials and cookies were reportedly validated by logging into victim accounts, after which operators collected additional account details relevant to monetization, including account characteristics and advertising-related information. Infrastructure associated with the operation also included support for Amazon-related data collection, although Facebook-focused theft appears to be the best-documented activity.
Victimology observed in public reporting included large infection volumes with notable concentrations in Vietnam, Russia, and Pakistan. StressPaint is best characterized as an infostealer with credential and session theft functionality, persistence on Windows hosts, and exfiltration of encrypted stolen data for downstream account hijacking and fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family in the same general class as CopperStealer.
A Trojan mentioned for comparison that attempts to extract and steal Facebook data from various URLs.
An information-stealing trojan hidden in a trojanized Windows painting application. It establishes persistence via Windows registry Run keys, copies Chrome Login Data and Cookies databases, extracts credentials and session cookies, encrypts the stolen data, and uploads it to a remote C2/control panel. The operators appear particularly interested in Facebook account data and session validation, with an additional Amazon-focused panel section observed.
Related malware family in the same ecosystem; written in Delphi, used similar techniques and strings as early SilentFade, and stole Facebook credentials and cookies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.