Kaspersky detailed an intrusion involving Predator the Thief after a client received an anonymous screenshot that had allegedly been exfiltrated from an internal system to the malware’s command-and-control server. The investigation identified Predator as a low-cost information stealer developed by Russian-speaking operators and marketed on Russian-language cybercrime forums, where it was promoted as a commodity tool for credential and data theft.
Technical analysis from Kaspersky and independent researcher Fumik0 showed the malware evolving from v2 to v3 with stronger obfuscation, anti-debugging and sandbox-evasion checks, broader browser theft support including Microsoft Edge and Internet Explorer, and a clipboard-stealing function inaccurately advertised by its operators as a keylogger. The reporting also described Predator’s commercial ecosystem, including sales on the VLMI forum, customer update channels on Telegram, frequent fully undetectable build refreshes, versioned samples from 3.0.3 through 3.0.7, and published detection material such as hashes and a YARA rule.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs discovered a phishing campaign in March 2019 targeting Russian speakers and delivering Predator the Thief, primarily version 3.0.8, via fake documents, ZIP archives, fake PDFs, and exploitation of the WinRAR ACE flaw CVE-2018-20250. The report linked the activity to a Russian-speaking actor associated with the username "nrjat" and documented the campaign's C2 infrastructure and malware delivery chain.
A screenshot allegedly exfiltrated by Predator was reportedly taken from an infected internal computer while an employee was browsing emails. The anonymous source said the image had been transferred to a Predator command-and-control server.
In mid-February, Kaspersky received an incident response request from a client after an anonymous source shared the screenshot from one of the client's internal computers. Kaspersky then conducted a full investigation of the infected machine, including memory dumps, event logs, and network indicators.
French malware researcher Fumik0_ analyzed Predator the Thief version 2.3.5. Kaspersky later cited this October 2018 work as part of Predator's documented evolution from v2 to v3.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcesecurelist.com
Open sourcefumik0.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.