logo

LOLI Stealer: Golang InfoStealer Found In The Wild

ID: ddd68ff6-172e-5faa-bcda-434314bc8773

STIX ID: report--ddd68ff6-172e-5faa-bcda-434314bc8773

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

LOLI Stealer is a recently observed Golang-based info stealer offered via a malware-as-a-service (MaaS) model that harvests browser credentials, cookies, histories, crypto-wallet files (multiple wallet paths referenced), Telegram and Steam session data, desktop text files, and screenshots; it packages stolen data into a ZIP, encodes it in Base64 with metadata, and posts it to a C2 at http://webStealer.ru/gate.php. Cyble's analysis examined a UPX-packed 64-bit Go binary (SHA256 provided), noted anti-analysis checks (WINE detection), enumerated targeted wallet and browser paths, captured the data exfiltration mechanism and panel screenshots, and published mitigations and IOCs including hashes and the C2 URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.