logo

“PupkinStealer” – New .NET Malware Harvests Browser Credentials and Sends Them via Telegram

ID: 814e825f-8598-5938-a637-428edd02553e

STIX ID: report--814e825f-8598-5938-a637-428edd02553e

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

PupkinStealer is a lightweight C#/.NET information stealer that extracts Chromium browser passwords, copies Telegram and Discord session tokens, collects selected desktop files and a screenshot, packages artifacts into a ZIP (with victim metadata), and exfiltrates the archive using the Telegram Bot API; the report provides IOCs (file hashes, Telegram bot token and exfiltration URL, file paths) and recommends EDR, outbound Telegram traffic monitoring, application whitelisting, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.