216.73.216.6

StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets and NFT Assets

· Published 21/04/2026 08:26 · Modified 21/04/2026 09:27

Export JSON

Essential information

Published
21/04/2026 08:26
Modified
21/04/2026 09:27
Tags
2026-04-21 crypto infostealer maas smart-contract stager api stepdrainer
Related entities
3 observables, 4 techniques (mitre), 4 others

Description

is a Malware-as-a-Service () platform engineered to steal digital assets from cryptocurrency wallets, including fungible tokens and high-value NFT collections. The malware supports more than 20 blockchain networks and incorporates multiple draining techniques, particularly abusing ERC-20 token permissions and NFT approval mechanisms. The platform includes automated asset transfer capabilities, compatibility with widely used mobile wallets, and encrypted logging via Telegram channels for attacker monitoring. is commercially distributed within cybercriminal ecosystems, with pricing models ranging from approximately $750 for full source code access to $150 for a shared version that imposes a 20% commission on successful thefts.

External references