Cybersecurity researchers warn of surge in Stealerium malware

Cybersecurity researchers warn of surge in Stealerium malware

Cybersecurity experts are sounding the alarm after a significant increase in cybercriminal activity involving Stealerium, a readily available open-source malware. 

Researchers at the security firm Proofpoint have observed a marked surge in campaigns using the information stealer to harvest sensitive data from victims across the globe.

According to Proofpoint’s threat data, Stealerium activity spiked between May and August 2025. The malware, along with its variants like Phantom Stealer and Warp Stealer, is capable of exfiltrating a wide array of data, including browser credentials, cryptocurrency wallets, Wi-Fi profiles, and VPN configurations. This stolen information is then sent to the attackers through various channels, such as Discord, Telegram, and email.

Recent campaigns have used diverse social engineering tactics to trick victims, including fake payment notices, legal threats, and travel bookings. The malware is often hidden within compressed files or common script attachments. Some variants even feature sextortion capabilities, capturing screenshots and webcam images when specific content is detected in open browser tabs.

Proofpoint noted that this is the first major resurgence of Stealerium since early 2023, highlighting its enduring appeal to cybercriminals looking for low-cost, high-impact tools. The malware’s accessibility and adaptability make it difficult for traditional defences to block, posing a serious threat to individuals and businesses alike.

Browse our latest issue

Intelligent CISO

View Magazine Archive