logo

Arcane stealer: We want all your data

ID: 79f84990-d07a-5ba4-9ce3-bd6e3d83e62a

STIX ID: report--79f84990-d07a-5ba4-9ce3-bd6e3d83e62a

Feed Name: Securelist by Kaspersky

Threat Score
72/100

Date Published: 2025-03-19

Date Updated: 2026-04-29

Author: AMR

...
...

The report describes the Arcane stealer campaign: malware distributed through YouTube cheat/crack links and a branded loader (ArcanaLoader) promoted via Discord, targeting Russian-speaking users. Arcane exfiltrates wide-ranging credentials and sensitive data (browsers, VPNs, gaming clients, crypto wallets, email), uses DPAPI and auxiliary tools (Xaitax) to recover browser keys, abuses remote-debugging to harvest cookies, and disables SmartScreen to aid execution. The actors regularly update the stealer and leverage social channels to recruit promoters; recommended mitigations include avoiding shady downloads and using robust security software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.