logo

Mystic Stealer Revisited

ID: 703d66bb-22f3-574b-bf53-03f04dd4965f

STIX ID: report--703d66bb-22f3-574b-bf53-03f04dd4965f

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes Mystic Stealer, a Windows information-stealing malware that uses Base64-encoded HTTP POST communications with a C2 to register infected hosts, receive binary-flag configuration, exfiltrate browser data (cookies, history, extensions), cryptocurrency wallet files, screenshots and arbitrary files, and to download additional executable payloads via a loader mechanism; the analysis includes C2 request/response formats, target lists, and notes on debug builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.