logo

Void Stealer: The Infostealer Malware Quietly Targeting Organizations in 2026

ID: 23a5bf95-e2d0-5c4f-a5d3-4afc6a5fe7c4

STIX ID: report--23a5bf95-e2d0-5c4f-a5d3-4afc6a5fe7c4

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Void Stealer is a mid-tier infostealer (MaaS) active since late 2025 that collects browser credentials, session cookies, crypto wallet seeds, messaging tokens, system fingerprints and more; it employs advanced evasion such as syscall-level EDR bypasses, runtime API resolution, encrypted configs and sandbox mutex checks, uses Steam profiles to resolve C2 infrastructure, delivers stolen logs to an admin panel and Telegram, and has multiple active affiliate campaigns with confirmed IOCs (e.g., citrusshop.icu, SteamID 76561199877608270).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.