Skip to main content
Mallory
Back to intelligence
credential-stealer-activitycredential-access-methodcybercrime-service-ecosystemdata-exfiltration-method

Infostealer Malware Resurgence Targeting Browser Credentials, Crypto Wallets, and Cloud-Synced Data

Updated 3mo agoFirst seen Feb 10, 20263 sources

Threat researchers reported continued growth in the infostealer ecosystem, with new families emphasizing theft of browser credentials, session cookies, and cryptocurrency wallet data. Zscaler ThreatLabz detailed Marco Stealer, first observed in June 2025, which profiles infected hosts (e.g., OS version, hardware ID, IP/geolocation) and targets browser data plus cryptocurrency wallet information from browser extensions; it also searches for sensitive files in local and cloud-synced locations, including folders associated with Dropbox and Google Drive, and uses anti-analysis measures such as runtime string decryption.

Separately, Cyfirma described LTX Stealer, a Windows-focused infostealer built around a bundled Node.js runtime and delivered via an Inno Setup installer (Negro.exe) that drops an unusually large (~271 MB) payload—reportedly to evade scanning heuristics. LTX Stealer targets Chromium-based browsers by extracting keys from Local State to decrypt saved passwords and cookies, collects screenshots, and stages data for exfiltration while using services such as Supabase (authentication) and Cloudflare (infrastructure masking). Flare’s research contextualized these developments as part of an “infostealer arms race,” observing multiple variants being marketed/updated across dark web forums and highlighting the downstream impact: analysis of 18.7M infostealer logs (2025) found enterprise SSO/IdP credentials in more than 10% of infections, and Verizon DBIR data cited by Flare linked infostealer credential exposure to a significant share of ransomware victimization; Flare also noted stealer developers rapidly adapting to Chrome’s evolving credential protections (e.g., post-v127 application-bound encryption and newer Chrome releases).

Share:
Infostealer Malware Resurgence Targeting Browser Credentials, Crypto Wallets, and Cloud-Synced Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 7, 20264mo ago

Stealer operators market Chrome 144 compatibility and evasion features

By the February 2026 forum snapshot, infostealer developers were advertising rapid adaptation to Chrome's newer protections, including claimed dynamic decryption support for Chrome 144. Sellers also aggressively promoted EDR and Windows Defender evasion capabilities to attract buyers.

Dark web snapshot shows active infostealer marketplace competition

A snapshot taken across multiple dark web forums found at least six infostealer variants being marketed, updated, or distributed for free. The activity reflected a mature, SaaS-like criminal ecosystem with tiered pricing, Telegram storefronts, and rapid versioned updates.

Jan 13, 20265mo ago

Google releases Chrome 144

Google Chrome version 144 was released, later becoming a benchmark used by infostealer developers to market compatibility with Chrome's evolving protections. Threat actors subsequently claimed dynamic decryption support for this version.

Jan 1, 20265mo ago

LTX Stealer emerges as a new Node.js-based infostealer

LTX Stealer emerged in early 2026 as a newly observed Windows information stealer that embeds a full Node.js runtime to execute malicious JavaScript without requiring Node.js to be installed. It targets Chromium-based browser credentials and cookies, cryptocurrency wallets, and also captures screenshots.

Jun 1, 20251y ago

Marco Stealer first observed targeting victims worldwide

Zscaler ThreatLabz reported that the Marco Stealer malware family was first observed in June 2025. The stealer targets browser data, cryptocurrency wallets, and sensitive files in local and cloud-synced folders such as Dropbox and Google Drive.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Infostealer Malware Resurgence Targeting Browser Credentials, Crypto Wallets, and Cloud-Synced Data | Mallory