PupkinStealer .NET Infostealer Using Telegram for Data Theft
Essential information
- Published
- 22/05/2025 13:09
- Modified
- 22/05/2025 14:59
- Tags
- 2025-05-22 credential-theft infostealer pupkinstealer session hijacking
- Related entities
- 1 observables, 10 techniques (mitre), 1 malware
Description
PupkinStealer is a newly identified .NET-based information-stealing malware that extracts sensitive data like web browser passwords and app session tokens, exfiltrating it via Telegram. It targets Chromium-based browsers, Telegram, and Discord, focusing on credential theft and session hijacking. The malware performs minimal system discovery, collects files from the desktop, and captures a screenshot. It packages stolen data into a ZIP archive and sends it to the attacker through Telegram's Bot API. PupkinStealer doesn't employ persistence mechanisms, relying on quick execution and low-profile behavior. Its primary evasion technique is leveraging legitimate Telegram infrastructure for communication.