Marco Stealer: The New “Data Raider” Targeting Crypto & Cloud Storage
ID: f6988552-fbbc-58b6-a9c3-398a68525eab
STIX ID: report--f6988552-fbbc-58b6-a9c3-398a68525eab
Feed Name: securityonline.info
Threat Score
Zscaler ThreatLabz describes 'Marco Stealer,' a June 2025 information-stealing malware that profiles victims and exfiltrates browser data, cryptocurrency extension keys, and local/cloud files (Dropbox, Google Drive). The malware employs string encryption, terminates analysis/security tools, encrypts stolen data with AES-256-CBC using a derived key, and sends bundles to an HTTP C2 — creating a significant financial and data-exfiltration risk to individuals and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
