logo

Unmasking Styx Stealer: How a Hacker’s Slip Led to an Intelligence Treasure Trove

ID: a63fde70-b739-55ef-8e54-4c150a51e72d

STIX ID: report--a63fde70-b739-55ef-8e54-4c150a51e72d

Feed Name: Check Point Research

Threat Score
70/100

Date Published: 2024-08-16

Date Updated: 2026-04-27

Author: alexeybu

...
...

Check Point Research uncovered Styx Stealer, a Phemedrone-derived info-stealer sold via subscription that exfiltrates browser credentials, crypto wallets, Telegram/Discord sessions, and implements a clipboard crypto-clipper, autorun, and anti-analysis checks; an OpSec error during debugging leaked the developer’s Telegram accounts, locations, and payment data, enabling attribution and linkage to an Agent Tesla operator (Fucosreal) and revealing active distribution attempts and customer payments totaling roughly $9.5K.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.