Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»‘Arkanix Stealer’ Malware Disappears Shortly After Debut
    Cybersecurity

    ‘Arkanix Stealer’ Malware Disappears Shortly After Debut

    adminBy adminFebruary 24, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new infostealer named ‘Arkanix Stealer’ operated as a malware-as-a-service (MaaS) enterprise in a one-shot campaign, Kaspersky says.

    Implemented in both C++ and Python, the malware emerged in October 2025, when its developer started advertising it in underground forum posts, but likely ceased operations in December, when its control panel and Discord channel disappeared.

    While short-lived, Arkanix Stealer did provide miscreants with broad information-stealing capabilities, collecting system and user information, application details, browser data, Telegram and Discord data, VPN information, and stealing files from specific directories.

    As part of the MaaS, users were provided with access to a control panel allowing them to configure payloads and access statistics.

    Users were provided with a browser post-exploitation tool named ChromElevator, delivered via a native C++ version of the malware that could also harvest cryptocurrency wallet data.

    The Python variant of the stealer, Kaspersky says, was deployed via a Python script, often bundled with PyInstaller or Nuitka, and could dynamically modify its configuration by making GET requests to a remote server.

    Advertisement. Scroll to continue reading.

    Arkanix Stealer could collect broad system information, including CPU, GPU, RAM, OS, screen, keyboard, and time zone data, along with details on the installed software, including antivirus and VPN applications.

    It could also target 22 browsers to harvest information such as history, autofill information, passwords, cookies, and 0Auth2 data, as well as Telegram messages and Discord credentials.

    The analyzed stealer sample also contained a self-spreading feature, acquiring a list of the victim’s Discord friends and channels via the Discord API, and sending a configured message to them.

    Kaspersky also observed the malware collecting credentials from known VPN clients, such as Mullvad VPN, NordVPN, ExpressVPN, and ProtonVPN.

    Using a pre-defined set of paths, the malware was seen exfiltrating files from multiple directories associated with the current user, packing them in a ZIP archive, and sending them to the command-and-control (C&C) server.

    The malware could also fetch additional modules from the C&C to expand its capabilities. These modules include a Chrome grabber, a wallet patcher, an extra collector, and a Python script placed in the startup folder to be executed at system boot.

    The native variant uses VMProtect, without code virtualization, implements anti-analysis features, collects RDP connection details, targets gaming files and clients for credential theft, captures screenshots, and exfiltrates browser data.

    Kaspersky identified two servers used to host the stealer panel and monitor victims, both secured via a sign-in page. The malware’s developer also maintained a Discord channel to interact with users and implemented a referral program to attract customers.

    “This campaign tends to be more of a one-shot campaign for quick financial gains rather than a long-running infection. The panel and the Discord chat were taken down around December 2025, leaving no message or traces of further development or a resurgence,” Kaspersky notes.

    Related: ‘SolyxImmortal’ Information Stealer Emerges

    Related: Infostealer Malware Delivered in EmEditor Supply Chain Attack

    Related: New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM

    Related: New Keenadu Android Malware Found on Thousands of Devices

    Arkanix debut Disappears Malware Shortly Stealer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWhat We’re Building with Starter Story
    Next Article How To Turn Performance Max Into An Ecommerce Growth Engine
    admin
    • Website

    Related Posts

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    AI went from assistant to autonomous actor and security never caught up

    March 3, 2026

    How Microsoft, partners are tackling ‘huge, huge task’ of making security software safer

    March 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    Google Clarifies How It Picks Thumbnails For Search, Discover

    March 3, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (572)
    • Privacy & Online Earning (80)
    • SEO & Digital Marketing (357)
    • Tech Tools & Mobile / Apps (709)
    • WiFi / Internet & Networking (103)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026
    Most Popular
    • Best High-Yield Checking Accounts for March 2026
    • This amazing ESP32 projector integrates with Home Assistant and displays whatever you want
    • SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
    • Google Clarifies How It Picks Thumbnails For Search, Discover
    • These budget-friendly wireless earbuds deliver a pleasant experience while still being easy on the wallet
    • AI went from assistant to autonomous actor and security never caught up
    • Segway Cube 1000 Portable Power Station hits lowest price ever!
    • How Microsoft, partners are tackling ‘huge, huge task’ of making security software safer
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.