MicroStealer Analysis: A Fast-Spreading Infostealer with Limited Detection
ID: 634855d9-899c-5710-9fa6-82a5211775ba
STIX ID: report--634855d9-899c-5710-9fa6-82a5211775ba
Feed Name: ANY.RUN's Cybersecurity Blog
Date Published: 2026-03-12
Date Updated: 2026-04-26
Author: nevergiveupcpp, 4OURUP and GridGuardGhoul
MicroStealer is an actively observed infostealer that uses a layered NSIS → Electron → Java (JAR) delivery chain to harvest browser credentials, session tokens, screenshots, and crypto wallet files, then exfiltrates data via Discord webhooks and attacker-controlled servers; the report provides static and dynamic analysis, persistence and privilege escalation behavior, anti-analysis checks, full IOCs (hashes, domains, webhook URL, API key), and MITRE ATT&CK mappings to aid detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
