logo

Dissecting Saintstealer

ID: bc6e0bcb-bb6b-53dd-81a1-30767293d96a

STIX ID: report--bc6e0bcb-bb6b-53dd-81a1-30767293d96a

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

**Executive summary:** This report analyzes Saintstealer, a C#.NET information stealer used since November 2021 that harvests browser credentials, cookies, autofill data, credit cards, VPN/Steam/Telegram artifacts and screenshots, employs anti-analysis and VM/sandbox detection, compresses stolen data into a password-protected ZIP, and exfiltrates results to a Telegram channel and a C2 (http://f0591243.xsph.ru / 141.8.197.42); the report provides technical details, targeted sites/browsers, MITRE mappings and IoCs to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.