logo

The Unknown Stealers: What’s Hidden Below the Radar

ID: 96608a97-c263-5338-b3af-8b0baeef393c

STIX ID: report--96608a97-c263-5338-b3af-8b0baeef393c

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report examines the evolving infostealer economy and provides a technical breakdown of Void Stealer — a C++ grab-and-go infostealer active in multiple affiliate campaigns that collects browser credentials, cookies, crypto wallets, desktop wallet files, messaging tokens, and system fingerprints. Void uses advanced evasion (runtime syscall/API resolution, XOR-encrypted config, mutex-based single-instance, and Steam-profile-based C2 resolution), uploads JSON/Base64-encoded logs to intermediate C2s with Telegram notification integration, and feeds stolen data into underground log markets that directly enable account takeover, initial access sales, and ransomware chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.