Void Stealer: The Infostealer Malware Quietly Targeting Organizations in 2026
ID: 23a5bf95-e2d0-5c4f-a5d3-4afc6a5fe7c4
STIX ID: report--23a5bf95-e2d0-5c4f-a5d3-4afc6a5fe7c4
Feed Name: SOCRadar Blog
Void Stealer is a mid-tier infostealer (MaaS) active since late 2025 that collects browser credentials, session cookies, crypto wallet seeds, messaging tokens, system fingerprints and more; it employs advanced evasion such as syscall-level EDR bypasses, runtime API resolution, encrypted configs and sandbox mutex checks, uses Steam profiles to resolve C2 infrastructure, delivers stolen logs to an admin panel and Telegram, and has multiple active affiliate campaigns with confirmed IOCs (e.g., citrusshop.icu, SteamID 76561199877608270).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
