Skip to main content
Mallory
MalwareRansomware

RisePro

RisePro is an information-stealing malware family active since at least late 2022. It is described as an infostealer used to harvest credentials and related data from infected systems, and reporting in the provided content places it among the most prevalent stealer families alongside Lumma, Vidar, Stealc, and RedLine. The malware is associated with theft of saved passwords, cookies, autofill data, authentication tokens, and other browser-stored information; one cited host artifact is a file named passwords.txt left on infected systems. The content also notes that stealer logs linked to RisePro can expose corporate and consumer credentials and have been used as a precursor to follow-on intrusions including credential stuffing, account takeover, and ransomware operations.

Observed delivery and infection vectors in the provided material include distribution through malicious GitHub repositories masquerading as cracked software, Discord-linked malware delivery chains, and pay-per-install distribution via PrivateLoader. One campaign described 17 malicious GitHub repositories using fake trust signals in README files and password-protected RAR archives; the extracted payload used a loader to inject RisePro version 1.6 into AppLaunch.exe or RegAsm.exe. Another report states loaders such as Smokeloader, PrivateLoader, and Amadey retrieved next-stage stealers including RisePro from Discord CDN-hosted payloads. RisePro was also reported in GitHub/Discord malware distribution amplified by the Stargazers Ghost network.

The content links RisePro to credential exposure in major intrusion activity. It is explicitly named by Mandiant and other reporting as one of the infostealers associated with previously exposed Snowflake credentials used in the UNC5537 campaign, alongside Vidar, RedLine, Raccoon Stealer, Lumma, and MetaStealer. Additional reporting cited in the content states credentials were obtained through RisePro and Vidar in some cases, and that compromised credentials from RisePro logs were sold or circulated through underground markets and channels. SCILabs also reported compromised credentials obtained via RisePro and Vidar being used in infrastructure related to Red Akodon phishing campaigns in Colombia.

Targeting in the provided content is broad rather than sector-specific: RisePro is described as infecting both consumer and corporate machines, with downstream impact on organizations whose employees or contractors use infected personal or unmanaged devices. The material highlights risk to cloud and enterprise environments when stolen credentials are reused against services such as VPNs, RDP, and Snowflake, especially where MFA is absent or bypassed through stolen session material. RisePro is also tracked in community IOC infrastructure collections such as C2 Tracker as "RisePro Stealer" infrastructure.

High-confidence indicators and artifacts directly mentioned in the content include the dropped file passwords.txt; malicious GitHub repositories themed around cracked software or legal/administrative lures; password-protected RAR/ZIP archives; injection into AppLaunch.exe or RegAsm.exe in the described GitHub campaign; and association with RisePro version 1.6 in that same activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence3

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

T1566PhishingEvidence1

“Attackers then can choose to disseminate these links through phishing emails, social media or other channels. When unsuspecting users click the links, they inadvertently download malware directly from Discord's CDN…”

Persistence

1 technique
T1078Valid AccountsEvidence3

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

Privilege Escalation

1 technique
T1078Valid AccountsEvidence3

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

Stealth

1 technique
T1078Valid AccountsEvidence3

В ноябре 2023 года APT29 (Midnight Blizzard) залезли в корпоративную среду Microsoft через password spraying единственного тестового облачного tenant без MFA... Initial Access и Credential Theft (T1078, T1621)... Valid Accounts (T1078...)

Credential Access

2 techniques
T1003OS Credential DumpingEvidence1

"Malware families like Redline, Raccoon, Vidar, Lumma, and Risepro infect... then systematically extract... saved passwords... session cookies... authentication tokens."

T1555Credentials from Password StoresEvidence2

"...compromised customer credentials purchased from cybercrime forums or obtained through information-stealing malware such as Lumma, MetaStealer, Raccoon, RedLine, RisePro, and Vidar..."

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

“once a malicious file is uploaded to Discord's CDN, a direct link is generated… users click the links… download malware directly from Discord's CDN… used… to download next-stage payloads.”

INDICATORS OF COMPROMISE

IOCs tracked for this family

223 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Other
223 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching223

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.