216.73.216.226

RAVEN STEALER UNMASKED: Telegram-Based Data Exfiltration

· Published 01/08/2025 11:48 · Modified 04/08/2025 10:49

Export JSON

Essential information

Published
01/08/2025 11:48
Modified
04/08/2025 10:49
Tags
2025-07-26 2025-08-01 browser data c++ credential-theft data exfiltration delphi github information-stealing infostealer octalyn stealer raven stealer telegram upx packing
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 2 malware

Description

is a modern malware developed in and C++, designed to extract sensitive data from victim machines. It targets Chromium-based browsers, extracting passwords, cookies, payment details, and autofill information. The malware uses a modular architecture and a built-in resource editor, allowing attackers to embed configuration details directly into the compiled payload. is packed using UPX, reducing its size and improving evasion against static detection. It executes in a hidden state, leaving no visible traces during runtime. The malware is actively distributed through repositories and promoted via a channel, which functions as both a development log and distribution platform. 's use of for C2-like behavior, paired with a clean user interface and dynamic module support, positions it as a commercially attractive tool within the commodity malware ecosystem.

External references