Arcane stealer: We want all your data
ID: 79f84990-d07a-5ba4-9ce3-bd6e3d83e62a
STIX ID: report--79f84990-d07a-5ba4-9ce3-bd6e3d83e62a
Feed Name: Securelist by Kaspersky
The report describes the Arcane stealer campaign: malware distributed through YouTube cheat/crack links and a branded loader (ArcanaLoader) promoted via Discord, targeting Russian-speaking users. Arcane exfiltrates wide-ranging credentials and sensitive data (browsers, VPNs, gaming clients, crypto wallets, email), uses DPAPI and auxiliary tools (Xaitax) to recover browser keys, abuses remote-debugging to harvest cookies, and disables SmartScreen to aid execution. The actors regularly update the stealer and leverage social channels to recruit promoters; recommended mitigations include avoiding shady downloads and using robust security software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
