Researchers uncovered a newly identified malware-as-a-service operation called Evil Stealer after its backend infrastructure was left exposed on Njalla-hosted systems, including an unauthenticated status API on port 8888 and a raw Next.js panel on port 3000. The exposed API revealed a sequential counter showing 310,194 processed credential logs within roughly six days, while the panel’s JavaScript also contained a cryptocurrency wallet drainer. Investigators linked the operation to domains including evilmirror[.]net and ofmhubintel[.]com, the latter tied to an OnlyFans creator scraper, indicating the actor was pursuing multiple monetization streams beyond credential theft.
The operator was identified with high confidence through poor operational security in a promotional video whose unstripped XMP metadata exposed the Windows username "moros", a Russian-language filename, and timestamps consistent with UTC+3 / Moscow time. Additional artifacts, including Russian keyboard indicators, shared registrar and hosting details, matching SSH HASSH fingerprints, and common Ubuntu templates, supported the assessment that the same Russian-speaking actor ran the linked infrastructure. Researchers also observed nearby suspicious services on the same hosting environment, including phishing and TLS interception infrastructure, although attribution for those adjacent systems was weaker; the malware payload and delivery chain for Evil Stealer itself had not yet been publicly identified.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
A social media post preview on May 8, 2026 referenced analysis of the Needle crypto-stealer stating that a plaintext API key embedded in the Rust malware exposed access to data on 1,932 victims and revealed the operator's withdrawal configuration. The available source is limited to the post title and does not include the underlying technical report.
On March 13, 2026, Breakglass expanded its reporting, detailing the exposed raw Next.js server on port 3000, bare Python monitoring endpoint on port 8888, and metadata in the promotional video that supported a Russian-speaking, UTC+3 operator assessment.
The same March 12 reporting said the operation combined multiple monetization streams: an infostealer, a cryptocurrency wallet drainer embedded in panel JavaScript, and a linked OnlyFans scraper branded OFM Hub Intel.
On March 12, 2026, Breakglass disclosed the newly identified Evil Stealer operation and attributed it with high confidence to an operator using the Windows username "moros," based on unstripped XMP metadata and Russian-language artifacts.
Within roughly six days of setup, Evil Stealer's unauthenticated status API on port 8888 revealed a sequential counter showing 310,194 processed credential logs, though investigators noted the count may have been frozen or migrated from earlier data.
Breakglass found a Candy Crush-themed StealC v2 binary communicating with live C2 domain joscramp[.]top on Google Cloud IP 34.41.139.193, and reported the server remained operational as of 2026-03-09.
A StealC v2 sample later analyzed by Breakglass was uploaded to MalwareBazaar on 2026-03-09, providing the basis for subsequent clustering and infrastructure analysis.
On March 4, 2026, infrastructure for Evil Stealer was rapidly established, including registration of evilmirror[.]net, issuance of a Let's Encrypt certificate, and deployment of a promotional video.
Breakglass reported that the StealC operator or affiliate had reused the same gate path and related infrastructure since at least March 2023, indicating the start of a longer-running financially motivated crime operation.
Developer fingerprints such as the copyright string "shmaer," product metadata, and recurring PDB path patterns linked 19 related binaries across StealC, RedLine Stealer, and Rhadamanthys dating back to 2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 110 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.