logo

MicroStealer Analysis: A Fast-Spreading Infostealer with Limited Detection 

ID: 634855d9-899c-5710-9fa6-82a5211775ba

STIX ID: report--634855d9-899c-5710-9fa6-82a5211775ba

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
72/100

Date Published: 2026-03-12

Date Updated: 2026-04-26

Author: nevergiveupcpp, 4OURUP and GridGuardGhoul

...
...

MicroStealer is an actively observed infostealer that uses a layered NSIS → Electron → Java (JAR) delivery chain to harvest browser credentials, session tokens, screenshots, and crypto wallet files, then exfiltrates data via Discord webhooks and attacker-controlled servers; the report provides static and dynamic analysis, persistence and privilege escalation behavior, anti-analysis checks, full IOCs (hashes, domains, webhook URL, API key), and MITRE ATT&CK mappings to aid detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.