LIVE NEWS
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
  • Elevance stock tumbles as CMS may halt Medicare enrollment
  • Wild spaces for butterflies to be created in Glasgow
  • You can now adjust how your caller card looks for calls on Android phones
  • TRON DAO expands TRON Academy initiative with Dartmouth, Princeton, Oxford, and Cambridge
  • Alex Mitchell: England scrum-half ruled out of Six Nations
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»‘Arkanix Stealer’ Malware Disappears Shortly After Debut
Cybersecurity

‘Arkanix Stealer’ Malware Disappears Shortly After Debut

primereportsBy primereportsFebruary 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
‘Arkanix Stealer’ Malware Disappears Shortly After Debut
Share
Facebook Twitter LinkedIn Pinterest Email


A new infostealer named ‘Arkanix Stealer’ operated as a malware-as-a-service (MaaS) enterprise in a one-shot campaign, Kaspersky says.

Implemented in both C++ and Python, the malware emerged in October 2025, when its developer started advertising it in underground forum posts, but likely ceased operations in December, when its control panel and Discord channel disappeared.

While short-lived, Arkanix Stealer did provide miscreants with broad information-stealing capabilities, collecting system and user information, application details, browser data, Telegram and Discord data, VPN information, and stealing files from specific directories.

As part of the MaaS, users were provided with access to a control panel allowing them to configure payloads and access statistics.

Users were provided with a browser post-exploitation tool named ChromElevator, delivered via a native C++ version of the malware that could also harvest cryptocurrency wallet data.

The Python variant of the stealer, Kaspersky says, was deployed via a Python script, often bundled with PyInstaller or Nuitka, and could dynamically modify its configuration by making GET requests to a remote server.

Advertisement. Scroll to continue reading.

Arkanix Stealer could collect broad system information, including CPU, GPU, RAM, OS, screen, keyboard, and time zone data, along with details on the installed software, including antivirus and VPN applications.

It could also target 22 browsers to harvest information such as history, autofill information, passwords, cookies, and 0Auth2 data, as well as Telegram messages and Discord credentials.

The analyzed stealer sample also contained a self-spreading feature, acquiring a list of the victim’s Discord friends and channels via the Discord API, and sending a configured message to them.

Kaspersky also observed the malware collecting credentials from known VPN clients, such as Mullvad VPN, NordVPN, ExpressVPN, and ProtonVPN.

Using a pre-defined set of paths, the malware was seen exfiltrating files from multiple directories associated with the current user, packing them in a ZIP archive, and sending them to the command-and-control (C&C) server.

The malware could also fetch additional modules from the C&C to expand its capabilities. These modules include a Chrome grabber, a wallet patcher, an extra collector, and a Python script placed in the startup folder to be executed at system boot.

The native variant uses VMProtect, without code virtualization, implements anti-analysis features, collects RDP connection details, targets gaming files and clients for credential theft, captures screenshots, and exfiltrates browser data.

Kaspersky identified two servers used to host the stealer panel and monitor victims, both secured via a sign-in page. The malware’s developer also maintained a Discord channel to interact with users and implemented a referral program to attract customers.

“This campaign tends to be more of a one-shot campaign for quick financial gains rather than a long-running infection. The panel and the Discord chat were taken down around December 2025, leaving no message or traces of further development or a resurgence,” Kaspersky notes.

Related: ‘SolyxImmortal’ Information Stealer Emerges

Related: Infostealer Malware Delivered in EmEditor Supply Chain Attack

Related: New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM

Related: New Keenadu Android Malware Found on Thousands of Devices

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleClaude faces ‘industrial-scale’ AI model distillation
Next Article Spirit Airlines to slash flights in bid to emerge from bankruptcy
primereports
  • Website

Related Posts

Cybersecurity

Samsung Unpacked 2026 live blog: Updates on Galaxy S26 Ultra, preorder deals, and pricing

February 25, 2026
Cybersecurity

Marquis sues SonicWall over backup breach that led to ransomware attack

February 25, 2026
Cybersecurity

Why ‘Call This Number’ TOAD Emails Beat Gateways

February 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.