logo

Omnistealer uses the blockchain to steal everything it can

ID: d7ac4717-4d4b-5b9a-8991-d7c5bdf78d58

STIX ID: report--d7ac4717-4d4b-5b9a-8991-d7c5bdf78d58

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-28

...
...

Omnistealer is an infostealer campaign that embeds encrypted commands and malware fragments in public blockchain transactions (TRON, Aptos, Binance Smart Chain) to create an undeletable, resilient staging and command‑and‑control channel. Once executed it harvests credentials from over 10 password managers, major browsers, cloud storage accounts, and more than 60 browser-based crypto wallets (including MetaMask and Coinbase Wallet); researchers estimate roughly 300,000 credentials have been compromised. Recommended mitigations include avoiding running untrusted code, using reputable password managers and MFA, isolating testing environments (VMs), and running up-to-date anti-malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.