Arkanix Stealer emerged as a previously undocumented infostealer offered under a malware-as-a-service (MaaS) model, promoted via dark web forum advertisements that directed buyers to a Discord server for coordination. Analysis identified multiple implants, including a native C++ variant with broad data-theft capabilities (e.g., system profiling and cryptocurrency wallet theft) and a Python implementation that can dynamically modify its configuration and is often packed to hinder analysis. The toolset also incorporated ChromElevator, a publicly available browser post-exploitation utility, and detections were mapped to families such as Trojan-PSW.Win64.Coins.* and Trojan.Python.Agent.*; the associated affiliate/referral program appeared to have been taken down, suggesting a short-lived operation.
Separately, January 2026 telemetry and case analysis on infostealer distribution highlighted ongoing, high-volume delivery via crack/keygen camouflage and SEO poisoning, with prominent families including LummaC2, Vidar, and ACRStealer. The reporting emphasized automated collection and analysis pipelines that extract C2/IOC data and support near-real-time blocking via an indicator service, underscoring that infostealer operations continue to rely on scalable distribution and obfuscation techniques even as individual MaaS offerings like Arkanix may be transient.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-19, Securelist published a detailed analysis of Arkanix Stealer, describing its Python and C++ variants, control panel behavior, data theft scope, and use of ChromElevator. The report also highlighted anti-analysis features, AMSI/ETW patching, and AES-GCM exfiltration in the C++ stealer.
On 2026-02-18, AhnLab published its January 2026 infostealer trend report summarizing activity collected through its internal systems and shared related indicators through its ATIP service. The report covered Windows and macOS delivery trends, including ClickFix-style terminal abuse on macOS.
In its January 2026 case study, AhnLab described MacSync Stealer being delivered through a fake GitHub page that executed a Base64-decoded zsh command to fetch additional scripts from sestraining.com. The chain ultimately ran an osascript stealer and exfiltrated collected data such as /tmp/osalogging.zip to command-and-control infrastructure.
During January 2026, AhnLab documented an ACRStealer variant that replaced hardcoded-key AES with ECDH key exchange on SECP256R1 and ChaCha20-Poly1305. The variant also added an X-Requests-Key header for session tracking.
In January 2026, AhnLab observed infostealer distribution heavily using crack/keygen themes and SEO poisoning, including abuse of legitimate but poorly managed WordPress sites. LummaC2, Vidar, and ACRStealer were the main families seen in this delivery channel.
Around December 2025, the Arkanix web panel and associated Discord presence appeared to go offline, suggesting the operation was short-lived. Its known infrastructure included arkanix[.]pw and arkanix[.]ru, both fronted by Cloudflare.
During late 2025, Arkanix operators distributed Python- and C++-based stealers using loader filenames suggesting phishing or social-engineering themes tied to Steam, Discord Nitro, and TikTok tools. The malware targeted browser data, messaging accounts, VPN credentials, wallet extensions, gaming credentials, and files of banking or cryptocurrency interest.
In October 2025, researchers found forum advertisements for a previously unknown malware-as-a-service infostealer called Arkanix Stealer. The offering included malware implants and a web-based control panel with configurable payloads and victim statistics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.