logo

NoMercy Stealer Adding New Features

ID: 70982bfc-9b79-51b7-ab44-10c38a71aec6

STIX ID: report--70982bfc-9b79-51b7-ab44-10c38a71aec6

Feed Name: Cyble Blog

Threat Score
65/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed “NoMercy,” a primitive, early-stage information stealer sold on Telegram that collects system data, screenshots, keystrokes, webcam images and audio, and registers infected hosts with a hardcoded C2. The report provides static details (SHA-256: 9ecc76d...), persistence behavior (copies to startup as WindowsKernalDrivers.exe), C2 format and indicators (http://six-clowns-sing-103-119-240-166.loca.lt, 193.34.76.44), notes recent feature additions (clipper and VPN client-stealer), and maps observed behaviors to MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.