logo

Alleged Meduza Stealer malware admins arrested after hacking Russian org

ID: 8e93741d-4ab8-5e1c-8d62-dd91471d4122

STIX ID: report--8e93741d-4ab8-5e1c-8d62-dd91471d4122

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-31

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Russian authorities announced arrests of three alleged creators/operators of the Meduza info-stealer, a malware-as-a-service that stole browser-stored credentials and crypto wallet data and could "revive" expired Chrome authentication cookies to facilitate account takeovers; the group is also linked to Aurora Stealer and reportedly developed a botnet capable of disabling security protections. The arrests followed a reported compromise of an institution in Astrakhan, which prompted a criminal case under Russian law, and authorities say they are continuing to identify accomplices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.