SilentDataCollector is a Windows data-theft component used in the StopAndProtect cybercrime operation, a modular toolkit that combines covert collection, lateral propagation, victim interaction, and in some cases ransomware deployment. It is best characterized as an infostealer focused on file discovery and targeted exfiltration rather than indiscriminate encryption. The malware inventories files across fixed, removable, and network drives, encrypts collected listings, and sends them to operator-controlled infrastructure. Operators can also task it to locate, compress, encrypt, and exfiltrate selected files from victim systems, enabling selective theft of documents and other high-value data.
Observed versions include broader surveillance and theft functions. These capabilities include keylogging, detection of valid email addresses, screenshot capture at regular intervals, network share mapping and unmapping, and automation of WhatsApp data collection against both web and desktop usage to identify specified contacts and capture contact details. Reporting indicates theft of password files and cryptocurrency wallet-related data in addition to file inventories and selected victim files.
SilentDataCollector is deployed late in a multi-stage infection chain that begins with ClickFix-style fake CAPTCHA social engineering on compromised WordPress sites, where victims are tricked into executing PowerShell commands. Subsequent PowerShell and .NET loader stages deliver the final payload set. The broader StopAndProtect operation has used thousands of compromised WordPress sites as distributed infrastructure for malware hosting, command-and-control, and storage of exfiltrated victim data. Campaign telemetry and exposed operator infrastructure indicate broad global victimization, with notable concentrations in the United States, Russia, and India. The malware has been associated with hands-on-keyboard activity in which operators direct collection objectives and interact with infected victims through companion tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
...operators could issue a WhatsApp search keyword to the stealer, which would then wait until the victim became inactive before automating both the desktop and web versions of WhatsApp to search for the named contact, open their contact information, and capture a screenshot...
SilentDataCollector : stealer complet (liste de fichiers, exfiltration ciblée ...) ... T1005 — Data from Local System (Collection)
SilentDataCollector : stealer complet ... keylogger ... T1056.001 — Input Capture: Keylogging (Collection)
The stealer then reads this command file and compresses, encrypts, and exfiltrates desired files to the base C&C server.
SilentDataCollector : stealer complet ... screenshots toutes les 30 secondes ... T1113 — Screen Capture (Collection)
The stealer waits until the victim becomes inactive and then uses WhatsApp automation to focus the search box, enter the specified keyword (contact name), open the contact information, and capture a screenshot.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing component that inventories files, performs targeted exfiltration, logs keystrokes, identifies valid emails, collects WhatsApp contacts, and captures screenshots every 30 seconds.
Data theft component that inventories drives, exfiltrates encrypted file lists, and can harvest specific files on operator command; newer versions also add keylogging, WhatsApp data collection, network share operations, and screenshot capture.
A data-theft module within the StopAndProtect toolkit that steals files, passwords, and cryptocurrency wallets, and in newer versions includes keylogging, network share mapping/unmapping, periodic screenshot capture, and automated WhatsApp contact searching with screenshot collection.
Data theft component that inventories files across drives, exfiltrates selected files, and in newer versions adds keylogging, WhatsApp contact exfiltration, network share mapping/unmapping, and periodic screenshot capture.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.