Security researchers have identified two new infostealer malware families, Stealka and AuraStealer, both targeting Windows users through deceptive distribution methods. Stealka is primarily spread via fake game cheats, mods, and pirated software hosted on legitimate platforms such as GitHub, SourceForge, and Softpedia, as well as through convincing fake websites. Once executed, Stealka is capable of hijacking accounts, stealing cryptocurrency, and installing crypto miners on victim devices by harvesting sensitive data from browsers, applications, and crypto wallets.
AuraStealer, on the other hand, is a malware-as-a-service (MaaS) offering that has gained traction on underground forums since mid-2025. It is marketed for its ability to steal data from over 110 browsers, 70 applications, and more than 250 browser extensions, with customizable configurations. Despite its advanced obfuscation and anti-analysis techniques, researchers have identified flaws that allow for detection and mitigation. Security experts have released deobfuscation scripts and configuration extractors to aid defenders in analyzing and countering AuraStealer's operations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
On December 18, 2025, Kaspersky published research describing Stealka's targeting of browsers, wallets, password managers, messaging apps, gaming clients, and VPN clients, and noted it could also install crypto miners. The company advised users to avoid pirated software, use antivirus protection, and reduce sensitive data stored in browsers.
On December 17, 2025, Gen Digital published a technical analysis of AuraStealer detailing its anti-analysis methods, encrypted configuration, C2 communications, and data-theft features. The report also shared reverse-engineering workflows, sample hashes, and suspected C2 domains.
By late 2025, AuraStealer was observed in 'Scam-Yourself' campaigns, including TikTok videos that tricked users into executing malicious PowerShell commands. These campaigns relied on users manually running attacker-provided commands to infect their own systems.
After its discovery, Stealka was identified as being spread through legitimate platforms including GitHub, SourceForge, and Softpedia, as well as convincing fake websites. The malware required victims to manually download and execute the malicious files.
Kaspersky said it discovered a new Windows infostealer called Stealka in November 2025. The malware was found masquerading as pirated software, game cheats, and mods to steal credentials, tokens, wallet data, and other sensitive information.
Gen Digital reported that the AuraStealer malware-as-a-service infostealer had been promoted on underground forums starting in July 2025. The Windows stealer was marketed as a low-footprint tool with broad data-theft capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcekaspersky.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.