logo

Server-Side Infostealers: How Initial Access Broker Pryx is Revolutionizing Infostealers

ID: 50fa5345-c536-5258-ae69-60d9e156f10a

STIX ID: report--50fa5345-c536-5258-ae69-60d9e156f10a

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-28

Author: InfoStealers

...
...

This report summarizes an interview with 'Pryx', an admin of the Hellcat ransomware group, who describes a server-side infostealer model that establishes Tor onion services on compromised hosts and allows attackers to remotely scrape credentials, tokens, and files; Pryx outlines modular hybrid tactics (lightweight client payloads + server-side harvesting), advanced techniques such as token hijacking and server-side AiTM, and a monetization model selling pre-compromised servers to ransomware and fraud operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.