logo

Creal: New Stealer Targets Crypto Users Via Phishing

ID: 39b0a039-4594-50a1-bde1-24013645c601

STIX ID: report--39b0a039-4594-50a1-bde1-24013645c601

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2024-10-24

Date Updated: 2026-07-17

...
...

**Creal Stealer** is an open-source Python-based information stealer actively abused by threat actors to harvest browser cookies, credentials, crypto wallets, chat/gaming app data and extensions; it was distributed via phishing sites and hosted payloads (Dropbox) with at least ~50 observed samples, includes extensive environment-evasion checks, persistence via Startup folder, and exfiltration over Discord/web file hosts—IoCs (file hashes, URLs) and mitigation recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.