logo

New Information Stealer Targeting Crypto Wallets: Key Threats

ID: fe1e923b-df07-50e1-819f-2567a40beea5

STIX ID: report--fe1e923b-df07-50e1-819f-2567a40beea5

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

Doenerium Stealer: Cyble CRIL observed a spear-phishing campaign that lures Office365 users to a malicious domain hosting a trojanized “Microsoft Windows Malicious Software Removal Tool” executable (masquerading as Node.exe). The malware implements sandbox/VM checks, kills analysis/virtualization tools, establishes persistence, harvests browser data, Discord tokens and crypto wallet addresses (including clipboard clipping), compresses collected artifacts and exfiltrates via a Discord webhook; the report includes technical analysis and IOCs (hashes, URLs, domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.