logo

'Styx Stealer' Blows Its Own Cover With Sloppy OpSec Mistake

ID: 21264b75-92a3-58b8-b3db-70a90a854644

STIX ID: report--21264b75-92a3-58b8-b3db-70a90a854644

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-21

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Check Point Research traced a new information stealer called Styx Stealer to a Turkey-based developer after an OpSec mistake leaked debugging data; researchers recovered Telegram bot tokens, chat IDs, contacts, and transaction records tying the author (Sty1x) to an Agent Tesla operator and revealing about $9,500 in purchaser payments. The report outlines Styx Stealer's capabilities to exfiltrate browser extension data, cryptocurrency wallets, Discord/Telegram/Steam sessions, documents, and system/location data, plus its obfuscation/evasion features and country-based kill-switches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.