logo

From fake Proton VPN sites to gaming mods, this Windows infostealer is everywhere

ID: b232e24d-7d0e-5349-8d92-ffb8cff4a90c

STIX ID: report--b232e24d-7d0e-5349-8d92-ffb8cff4a90c

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2026-04-15

Date Updated: 2026-04-28

...
...

This report describes multiple active campaigns distributing NWHStealer, an infostealer that harvests browser data, saved passwords, and cryptocurrency wallet files. Attackers distribute malicious archives via fake VPN websites, code- and file-hosting platforms, compromised YouTube links, and free web hosting (onworks.net), using loaders such as MSI/Node.js, DLL hijacking, process hollowing (RegAsm), in-memory execution, and a CMSTP UAC bypass; the report includes hashes, domains, URLs, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.