Target Industry
Indiscriminate.
Overview
Security researchers at CYFIRMA have produced an analysis of a .NET-based information-stealing malware. PupkinStealer is designed to harvest sensitive user data, including browser credentials, desktop files, messaging sessions (Telegram and Discord), and desktop screenshots.
Impact
PupkinStealer malware is likely to pose as a high impact to both individuals and organisations. It compromises user privacy and can lead to identity theft and financial fraud. For organisations, the theft of credentials and sensitive data increases security risks, potentially resulting in data breaches, reputation damage, and substantial financial losses.
Exploitation
The PupkinStealer malware is typically deployed through phishing emails, malicious attachments, or compromised websites. The malware uses decryption keys from Chromium-based browsers to extract saved login credentials. It hijacks sessions and copies the Telegram’s data folder, which extracts Discord tokens for unauthorised access. The stolen data is saved into a ZIP archive and sent to a remote server via Telegram Bot API.
Indicators of Compromise
The table below outlines some of the indicators of compromise (IoC) taken from GBHackers:
| IoC Type | IoC Value |
| File Path | %APPDATA%\Temp$Username]\Grabbers\Browser\passwords.txt |
| MD5 | fc99a7ef8d7a2028ce73bf42d3a95bce |
| SHA-256 | 9309003c245f94ba4ee52098dadbaa0d0a4d83b423d76c1bfc082a1c29e0b95f |
| Telegram Bot Token | 8013735771:AAEUrTgQsAmiAsXeDN6mehDfo3vEg-kCM |
| URL | https[:]//api[.]telegram[.]org/bot[BotToken]/sendDocument?chat_id=7613862165&caption |
Containment, Mitigations & Remediations
It is highly recommended to Implement robust cyber security measures, such as endpoint security solutions, network monitoring, and user education to mitigate the risks associated with PupkinStealer.
Threat Landscape
The possible risk to organisations of PupkinStealer malware is substantial. This is due to its design for rapid deployment and data harvesting without complex obfuscation or persistence mechanisms. It reflects the growing sophistication of malware and the use of platforms like Telegram for command-and-control operations.
Threat Group
The threat actor group behind PupkinStealer is attributed to a developer known as Ardent. This attribution is based on embedded code strings and other identifiers found within the malware. Ardent is believed to be a Russian-speaking developer, which aligns with the use of Telegram for exfiltration and other operational details
Further Information













