logo

PurpleWave—A New Infostealer from Russia

ID: 301fa34f-ca9b-5f55-b11c-e73e6d0c8b8d

STIX ID: report--301fa34f-ca9b-5f55-b11c-e73e6d0c8b8d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

PurpleWave is an actively available C++ infostealer sold on Russian cybercrime forums that silently installs on Windows systems, harvests browser credentials, cookies, cards, autofill data, screenshots, Telegram and Steam session files, Electrum wallet data, and system information, and communicates with live C2 servers to upload stolen data and download additional modules; the report provides detailed technical analysis, MITRE ATT&CK mappings, sandbox coverage, and multiple IOCs (file hashes and C2 URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.