logo

Fake ProtonVPN, game mod sites spread NWHStealer in new Windows malware campaign

ID: 1ed5b299-2925-5af1-858b-f1a36af1fa66

STIX ID: report--1ed5b299-2925-5af1-858b-f1a36af1fa66

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

NWHStealer campaigns are actively distributing an information-stealing trojan by masquerading as legitimate installers (Proton VPN, OhmGraphite, Sidebar Diagnostics, etc.) and hosting payloads across lookalike domains, GitHub/GitLab, MediaFire, SourceForge and YouTube-linked downloads; the malware uses DLL hijacking, process hollowing, in-memory/decrypted loaders, scheduled tasks, CMSTP UAC bypass, and Telegram-based dead drops to persist and exfiltrate AES-CBC–encrypted browser credentials and cryptocurrency wallet data to C2 servers — users should only download from official vendors, verify signatures, and use browser/site protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.