logo

Bandit Stealer

ID: 8c62da2a-480b-518a-8da8-ab7ef48e47d7

STIX ID: report--8c62da2a-480b-518a-8da8-ab7ef48e47d7

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Bandit Stealer is an information-stealer that employs extensive anti-VM and anti-debugging checks to evade analysis and targets a wide range of browsers, desktop and extension cryptocurrency wallets, FTP and email clients, and system artifacts to exfiltrate credentials, cookies, payment data, keystrokes and clipboard contents. Stolen data is aggregated into files under %appdata%\local (country_code + IP folder) and the malware uses Windows APIs and utilities (CryptUnprotectData, GetAdaptersAddresses, WMIC, CreateToolhelp32Snapshot) to collect system identifiers and avoid sandboxed environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.