A new information-stealing malware named Arkanix has emerged, targeting users for short-term financial gain. Arkanix is distributed primarily through Discord, masquerading as legitimate tools or being shared on online forums. The malware has evolved rapidly, with an initial Python-based version and a more advanced C++ implementation now available as a "Premium" option. The C++ version leverages process injection techniques to bypass Chrome's app-bound encryption, allowing it to extract sensitive data such as credentials, VPN accounts, Steam accounts, screenshots, and Wi-Fi credentials. The threat actors behind Arkanix also employ obfuscation tools like VMProtect to evade detection and offer a web-based control panel accessible via invite codes distributed on Discord.
Security researchers have noted that Arkanix is likely designed for quick, short-term profit, with its operators focusing on rapid development and distribution rather than long-term campaigns. The malware's web panel provides various options for managing stolen data and customizing payloads, indicating a level of sophistication in its operation. The use of C++ process injection to defeat Chrome's encryption mechanisms marks a notable advancement in stealer malware capabilities, raising concerns about the effectiveness of current browser security measures against such threats.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting highlighted that Arkanix’s native C++ version can bypass Google Chrome’s App-Bound Encryption using process injection. This added technical detail emphasized the stealer’s more advanced browser-credential theft capability.
G DATA reported a newly discovered information-stealing malware family called Arkanix, distributed mainly via Discord and online forums for short-term financial gain. Their analysis described both Python and C++ variants, the malware’s data-theft capabilities, infrastructure, and indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.