logo

Prynt Stealer Spotted In the Wild

ID: ea69dbae-7e46-5fc9-ae3d-e973c134e0b8

STIX ID: report--ea69dbae-7e46-5fc9-ae3d-e973c134e0b8

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs analyzed Prynt Stealer, a recently advertised and customizable .NET infostealer that steals browser credentials, cookies, autofill, crypto wallets, messaging sessions, gaming and FTP data, screenshots, and Wi‑Fi credentials; it uses obfuscation (rot13 on Base64), AES-encrypted strings, in-memory AppDomain loading, and exfiltrates compressed data via a Telegram bot. The report includes technical details of targeted applications, persistence/collection behavior, optional modules (keylogger, clipper, anti-analysis), recommended mitigations, MITRE ATT&CK mappings, and multiple malware hashes as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.