Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Arkanix Stealer pops up as short-lived AI info-stealer experiment
    Cybersecurity

    Arkanix Stealer pops up as short-lived AI info-stealer experiment

    adminBy adminFebruary 22, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hand
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hand

    An information-stealing malware operation named Arkanix Stealer, promoted on multiple dark web forums towards the end of 2025, was likely developed as an AI-assisted experiment.

    The project included a control panel and a Discord server for communication with users, but the author took them down without notification, just two months after the operation began.

    Arkanix offered many of the standard data-stealing features that cybercriminals are used to, along with a modular architecture and anti-analysis features.

    Wiz

    Kaspersky researchers analyzed the Arkanix stealer and found clues indicating LLM-assisted development, which “might have drastically reduced development time and costs.”

    Signs of LLM involvement in coding
    Signs of LLM traces in coding
    Source: Kaspersky

    The researchers believe that Arkanix was a short-lived project for quick financial gains, which makes detection and tracking much more difficult.

    Arkanix appears online

    Arkanix started being promoted on hacker forums in October 2025, offering two tiers to potential customers: a basic level with a Python-based implementation, and a “premium” one with a native C++ payload using VMProtect protection, integrating AV evasion and wallet injection features.

    Arkanix promoted on hacker forums
    Arkanix promoted on hacker forums
    Source: Kaspersky

    The developer set up a Discord server that acted as a forum for the community around the project to receive updates, provide feedback for proposed features, and receive help.

    Also, a referral program was established to promote the project more aggressively, giving referrers an extra free hour of premium access, while potential new customers received one week of free access to the “premium” version.

    Referral options from within the dashboard
    Referral options from within the dashboard
    Source: Kaspersky

    Data-stealing capabilities

    Arkanix malware can collect system information, steal data stored in the browser (history, autofill info, cookies, passwords), and cryptocurrency wallet data from 22 browsers. Kaspersky researchers say that it can also extract 0Auth2 tokens on Chromium-based browsers.

    Additionally, the malware can steal data from Telegram, steal Discord credentials, spread via the Discord API, and send messages to the victim’s friends/channels.

    Arkanix also targets credentials for Mullvad, NordVPN, ExpressVPN, and ProtonVPN, and can archive files from the local filesystem to exfiltrate them asynchronously.

    Additional modules that can be downloaded from the command-and-control include a Chrome grabber, a wallet patcher for Exodus or Atomic, a screenshots tool, HVNC, and stealers for FileZilla and Steam.

    Partial list of targeted extensions
    Partial list of targeted crypto extensions
    Source: Kaspersky

    The “premium” native C++ version adds RDP credential theft, anti-sandbox and anti-debugging checks, WinAPI-powered screen capturing, and also targets Epic Games, Battle.net, Riot, Unreal Engine, Ubisoft Connect, and GOG.

    The higher-tier variant also delivers the ChromElevator post-exploitation tool, which injects into suspended browser processes for data theft and is designed to bypass Google’s App-Bound Encryption (ABE) protection for unauthorized access to user credentials.

    The purpose of the Arkanix stealer experiment remains unclear. The project may be an attempt to determine how LLM assistance can improve malware development and how quickly new features can be shipped to the community.

    Kaspersky’s assessment is that Arkanix is “more of a public software product than a shady stealer.”

    The researchers provide a comprehensive list of indicators of compromise (IoCs) that include hashes for detected files, along with domains and IP addresses.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    Arkanix experiment Infostealer pops shortlived Stealer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleDon't install another Linux distro until you've tried an immutable one
    Next Article OpenAI’s first ChatGPT gadget could turn out to be a smart speaker with a camera attached
    admin
    • Website

    Related Posts

    FBI arrests suspect linked to $46M crypto theft from US Marshals

    March 5, 2026

    Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises

    March 5, 2026

    DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More

    March 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Cisco issues emergency patches for critical firewall vulnerabilities

    March 5, 2026

    FBI arrests suspect linked to $46M crypto theft from US Marshals

    March 5, 2026

    The Verified Source Pack Agents Trust First

    March 5, 2026

    BBC Sport – News & Live Scores 9.6.0.30534 APK Download by British Broadcasting Corporation

    March 5, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (618)
    • Privacy & Online Earning (92)
    • SEO & Digital Marketing (393)
    • Tech Tools & Mobile / Apps (755)
    • WiFi / Internet & Networking (111)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Cisco issues emergency patches for critical firewall vulnerabilities

    March 5, 2026

    FBI arrests suspect linked to $46M crypto theft from US Marshals

    March 5, 2026

    The Verified Source Pack Agents Trust First

    March 5, 2026
    Most Popular
    • Cisco issues emergency patches for critical firewall vulnerabilities
    • FBI arrests suspect linked to $46M crypto theft from US Marshals
    • The Verified Source Pack Agents Trust First
    • BBC Sport – News & Live Scores 9.6.0.30534 APK Download by British Broadcasting Corporation
    • Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises
    • What AI means for the future of SEO [Expert Tips & Interview]
    • 200+ AI audits reveal why some industries struggle in AI search
    • DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.