Cisco Talos and BleepingComputer reported that ZingoStealer, a new .NET-based information stealer promoted by the Haskers Gang, was released for free in Russian-speaking cybercrime channels, increasing the likelihood of broad criminal adoption. The malware has been distributed through lures including game cheats, cracks, key generators, pirated software, and YouTube-hosted bait, primarily targeting home users while avoiding infections in CIS countries. Researchers said the operation also relied heavily on Telegram for build distribution, log handling, and exfiltration support.
ZingoStealer collects browser data, host and system information, collaboration-platform tokens, cryptocurrency wallet extensions and wallet files, and desktop files, then archives the data and exfiltrates it to attacker-controlled infrastructure. Researchers also found that it functions as a loader for additional payloads, most notably RedLine Stealer and an XMRig-based Monero miner known as ZingoMiner, giving operators multiple ways to monetize compromised systems. Talos further noted that the group offered an ExoCrypt crypter service to help evade antivirus detection, and that the malware author was later seen transferring ownership of the project and offering the source code for sale.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
An update dated 2022-04-14 stated that ownership of the ZingoStealer project was being transferred to a new threat actor for further development. Cisco Talos and BleepingComputer both reported the change in control after the source-code sale offering.
In March 2022, Haskers Gang introduced ZingoStealer in the wild and offered the .NET infostealer for free in its Telegram and Discord communities. The malware was promoted in Russian-speaking cybercrime channels as a ready-to-use stealer.
Cisco Talos said Haskers Gang has been active since at least January 2020. The group later used Telegram and Discord to distribute tooling and coordinate activity.
The malware author offered to sell the ZingoStealer source code for $500, negotiable. This sale attempt was later linked to a transfer of the project to another threat actor.
A recent ZingoStealer release added XMRig-based Monero mining capability as another monetization path. Talos observed delivery of an XMRig injector, and BleepingComputer noted the malware used PowerShell to add Defender exclusions and run the miner.
Cisco Talos observed ZingoStealer downloading and executing additional malware from attacker-supplied URL lists. The most common second-stage payload observed was RedLine Stealer.
Threat actors offered a pre-built ZingoStealer option bundled with the ExoCrypt crypter for 300 rubles. This service was intended to help evade antivirus detection.
After its release, ZingoStealer was spread through software cracks and video game cheats, including promotions on YouTube. These lures primarily targeted home users.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.