Russian authorities arrested three individuals in Moscow suspected of developing and operating the Meduza Stealer malware, a sophisticated information-stealing tool distributed via a malware-as-a-service model. The suspects, described as young IT specialists, allegedly created and sold the malware on hacker forums, enabling cybercriminals to steal account credentials, cryptocurrency wallet data, and other sensitive information from victims' web browsers. The arrests followed an incident where the group targeted an institution in Astrakhan, Russia, leading to a criminal investigation under Russian law. Police seized computer equipment, phones, and bank cards during raids, and officials noted that the group may have also developed additional malware for disabling antivirus protection and building botnets.
Meduza Stealer first appeared in 2023 and quickly gained notoriety for its technical capabilities, including the ability to revive expired Chrome authentication cookies to facilitate account takeovers. The malware has been linked to attacks in multiple countries, including Ukraine and Poland, and was distributed through Russian-language hacking forums and Telegram channels. Ukrainian officials have attributed attacks on military and government entities to Meduza Stealer, and researchers have observed infections both inside and outside Russia. The suspects now face up to four years in prison if convicted.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Russian authorities publicly disclosed the case on or around October 31, 2025, stating that the suspects had worked on Meduza for about two years and tying the investigation to the Astrakhan-region attack.
During the arrests, police seized computing equipment, communication devices, payment cards, and other financial items, and said the suspects had also developed another malware strain designed to disable security tools and build botnets.
On October 30, 2025, Russian law enforcement detained three suspects in Moscow and the surrounding region for allegedly developing, distributing, and using the Meduza Stealer malware.
Russian authorities linked the suspects to a breach of a government institution or organization in Russia's Astrakhan region, with one report specifying the incident occurred in May and involved theft of classified data.
Russian authorities and reporting said the Meduza Stealer malware had been active since mid-2023 and was marketed for about two years on Russian-language hacker forums and Telegram channels as a malware-as-a-service offering.
Researchers linked Meduza Stealer to credential and cryptocurrency theft campaigns affecting victims in Ukraine, Poland, and Russia, showing the malware's broader operational use beyond its sale on forums.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedatabreaches.net
Open sourcego.theregister.com
Open sourcegovinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcehackread.com
Open sourcebankinfosecurity.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.