logo

Prynt Stealer’s Backdoor Exposed

ID: 44bfa659-ac27-5533-88c0-32953c2a88a6

STIX ID: report--44bfa659-ac27-5533-88c0-32953c2a88a6

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz reports that Prynt Stealer is a .NET information-stealer derived from AsyncRAT and StormKitty which harvests credentials, browser data, and other sensitive files and exfiltrates them via Telegram; the builder contains a hardcoded backdoor that also forwards stolen logs to the author's Telegram channel, increasing exposure to multiple threat actors. The analysis documents near-identical variants (WorldWind, DarkEye), a leaked/backdoored builder that can deploy additional malware (DarkEye, LodaRAT), anti-analysis behaviors, and publishes IOCs (SHA256 hashes, Telegram tokens/chat IDs, C2 URLs) to enable detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.