Raven Stealer infostealer distributed via underground forums and cracked software
Malware Activity
Summary
Hide ▲
Show ▼
The Raven Stealer infostealer is now being distributed through underground forums and cracked software, creating a theft risk for Chromium-based browser credentials and application data. It targets Google Chrome, Microsoft Edge, Brave, and similar apps to collect cookies, autofill data, browsing history, and saved logins. The malware routes stolen data through Telegram for C2 and exfiltration, which can reduce visibility for defenders. It matters because the tool is built for stealth and can enable account compromise and follow-on abuse.
Related Happenings
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
CrystalRAT Telegram-promoted malware-as-a-service
Malware Activity
H score28
First: 02.04.2026 02:17
Last: 02.04.2026 02:17
Sources 1
About this happening:
The CrystalRAT malware-as-a-service is being promoted on Telegram and YouTube with remote access, data theft, keylogging, and clipboard hijacking, incr...
CrystalRAT Telegram-promoted malware-as-a-service
Malware ActivityAbout this happening: The CrystalRAT malware-as-a-service is being promoted on Telegram and YouTube with remote access, data theft, keylogging, and clipboard hijacking, incr...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware Activity
H score29
First: 31.03.2026 17:51
Last: 31.03.2026 17:51
Sources 1
About this happening:
The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware ActivityAbout this happening: The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Torg Grabber browser-extension theft activity
Malware Activity
H score36
First: 25.03.2026 20:32
Last: 25.03.2026 20:32
Sources 1
About this happening:
The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Torg Grabber browser-extension theft activity
Malware ActivityAbout this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Timeline
-
17.09.2025 15:06 2 articles · 10mo ago
Point Wild discloses Raven Stealer
Initial DisclosurePoint Wild's Lat61 Threat Intelligence disclosed Raven Stealer, a lightweight infostealer written primarily in Delphi and C++ that is spreading through underground forums and cracked software to target Chromium-based browsers such as Google Chrome, Microsoft Edge, and Brave, along with other applications. The malware harvests cookies, autofill data, browsing history, saved passwords, session cookies, and system details, uses a Telegram Chat ID and Bot Token for command-and-control and exfiltration, decrypts browser data with the Edge browser Local State AES key, compresses stolen artifacts into a .ZIP archive, and attempts to remove traces by rebooting into Safe Mode with Networking and using UltraAV.
Show sources
- Raven Stealer Scavenges Chromium Data via Telegram — www.darkreading.com — 17.09.2025 15:06
- Raven Stealer Scavenges Chromium Data via Telegram — www.darkreading.com — 17.09.2025 15:06