A new infostealer malware known as Shuyal Stealer has been identified by cybersecurity researchers, targeting a wide range of web browsers to harvest sensitive user data. The malware is capable of extracting login credentials from at least 17 to 19 different web browsers, significantly broadening its potential victim pool. Shuyal Stealer is designed to collect not only browser credentials but also Discord authentication tokens, clipboard contents, and screenshots, providing attackers with a comprehensive view of the victim's activities and online accounts. The malware leverages Windows Management Instrumentation commands to profile infected systems, gathering detailed information about disks, input devices, and display configurations, which can be used for further targeted attacks or identity theft. To maintain persistence, Shuyal Stealer copies its executable into the Windows Startup folder using the CopyFileA API, ensuring it runs on system reboot. For data exfiltration, the malware compresses stolen files using PowerShell and transmits them via a hardcoded Telegram bot, utilizing a specific bot token and chat ID to deliver the data directly to the attacker. After successful exfiltration, Shuyal Stealer deletes the archive and clears traces to hinder forensic analysis. A notable stealth feature of the malware is its ability to disable the Windows Task Manager by both terminating its processes and modifying the registry, making it difficult for users to detect or terminate the malicious activity. The malware specifically targets the "Login Data" files within browser directories, executing SQL queries to extract stored credentials and URLs. Researchers have highlighted the efficiency and thoroughness of Shuyal Stealer in both data theft and anti-detection measures. The use of Telegram for exfiltration provides attackers with a reliable and anonymous channel for receiving stolen data. The malware's ability to collect contextual data, such as screenshots and clipboard contents, increases the risk of complete account takeovers and more sophisticated social engineering attacks. Security experts recommend heightened vigilance and the implementation of endpoint protection solutions capable of detecting such stealthy infostealers. Organizations and individuals are urged to monitor for unusual system behavior, especially the inability to access Task Manager, which may indicate infection. The discovery of Shuyal Stealer underscores the evolving tactics of cybercriminals in developing malware that combines broad data theft capabilities with advanced evasion techniques. The campaign demonstrates the ongoing threat posed by infostealers that target both personal and enterprise environments. Researchers continue to analyze the malware's infrastructure and distribution methods to better inform defensive strategies. The incident highlights the importance of regular software updates, user education, and robust incident response plans to mitigate the impact of such threats.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Security guidance was released recommending Safe Mode with Networking, antivirus or specialized malware-removal tools, manual inspection of malicious Startup folder files, auditing command-line logs, and restricting script execution policies. The malware was also reported as detected under the name Trojan.W64.100925.Shuyal.YR.
Public reports disclosed that Shuyal Stealer targets credentials from 17 to 19 web browsers, including Chrome, Edge, Opera, and Yandex, using SQL queries against browser SQLite databases. The same reporting said the malware is spread through malicious websites and phishing emails and uses WMI-based reconnaissance and PowerShell-assisted data packaging for exfiltration.
Point Wild's Lat61 Threat Intelligence Team identified a new infostealer dubbed Shuyal Stealer and documented its capabilities, including theft of browser credentials, Discord tokens, clipboard data, screenshots, and system profiling. The malware was found to use persistence via the Windows Startup folder, disable Task Manager, and exfiltrate data through a hardcoded Telegram bot/API while deleting traces to hinder analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.