Researchers detailed multiple credential-theft threats targeting browsers, wallets, messaging apps, and copied secrets. Stealc, a malware-as-a-service infostealer marketed on Russian-speaking forums, was shown stealing browser credentials, cookies, autofill data, payment cards, cryptocurrency wallet extensions and files, Discord tokens, Telegram sessions, Steam files, Outlook credentials, and screenshots, while using anti-analysis checks, RC4-protected configuration data, and HTTP-based command-and-control to exfiltrate data and fetch second-stage payloads. Separately, Threatray linked the Rust-based Windows stealer KuinaExtractor to its newer k0to branding, finding the same malware family behind builds that steal browser data, saved credentials, gaming sessions, crypto-wallet data, Discord tokens, Windows Credential Manager data, and Wi-Fi details, while adding privilege-escalation attempts, Microsoft Defender tampering, and stronger concealment.
A parallel browser-based campaign used malicious updates to the Chrome extension "VPN Go: Free VPN" and the Firefox extension "Free VPN by VPN GO" to capture clipboard contents and send them to hardcoded HTTP endpoints. Because the extensions still provided visible VPN or proxy functionality, the clipboard theft was harder for users to spot, putting copied passwords, MFA recovery codes, seed phrases, API keys, OAuth tokens, and banking details at risk. The reports advised organizations to remove the extensions, review synced browser profiles, revoke sessions, rotate exposed credentials and secrets from a clean device, and treat any Windows system that executed the stealers as a full infostealer compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Two browser extensions, Chrome's "VPN Go: Free VPN" and Firefox's "Free VPN by VPN GO," were reported to have added clipboard-stealing functionality in later updates and exfiltrated copied data to hardcoded HTTP endpoints. Socket reported the extensions to Google and Mozilla and advised users to remove them and rotate exposed secrets.
Threatray's analysis connected KuinaExtractor and k0to through code similarity, mutexes, build paths, Telegram contact handles, and related experiments, concluding they are the same Rust-based infostealer family rather than separate threats.
A June 17, 2026 k0to build emphasized stealth over new theft capabilities, adding XOR-obfuscated strings, analyst-tool checks via PowerShell window titles, and a self-contained HTTP stack.
Stealc was sold as a Malware-as-a-Service on Russian-speaking underground forums starting in January 2023. The malware was attributed to a developer using the name Plymouth.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcetrojan-killer.net
Open sourcefarghlymal.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.