logo

New Arcane infostealer infects YouTube, Discord users via game cheats

ID: 3b933e81-b32a-558a-8df0-c8a81edfdf33

STIX ID: report--3b933e81-b32a-558a-8df0-c8a81edfdf33

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Arcane is a newly discovered information‑stealing malware campaign (active since Nov 2024) that harvests a broad set of user data — VPN and gaming credentials, messaging and email data, browser logins/cookies, crypto wallets, screenshots and Wi‑Fi passwords — and is distributed via social‑engineering on YouTube and Discord (password‑protected archives and a fake downloader, ArcanaLoader). Kaspersky telemetry shows most infections in Russia, Belarus and Kazakhstan; the campaign replaced a previous stealer (VGS/Phemedrone) and uses obfuscation and Windows Defender evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.