Arkanix Stealer: a C++ & Python infostealer
ID: 4651264b-ae24-5ced-bf1c-4adaaf31f536
STIX ID: report--4651264b-ae24-5ced-bf1c-4adaaf31f536
Feed Name: Securelist by Kaspersky
This report analyzes the Arkanix Stealer, a malware-as-a-service information stealer discovered in October 2025 that operated via a panel and Discord-based marketing; it documents Python and native C++ implants (including a bundled ChromElevator component), phishing-oriented distribution, extensive data exfiltration capabilities (browsers, wallets, Telegram/Discord, VPNs, RDP, gaming clients, screenshots), modular secondary payloads, C2 infrastructure (arkanix.pw / arkanix.ru), and multiple file hashes and IoCs; the service appeared to be taken down by December 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
