A new stealer has been discovered, and it seems a new version of Phemedrone Stealer, but it's more potent and it's capability is more adept that the original, and it is called, Styx Stealer. What makes it more powerful than it's predecessor Phemedrone Stealer, is that
Styx Stealer is a powerful malware capable of stealing saved passwords, cookies, and auto-fill data from various Chromium- and Gecko-based browsers, data from browser extensions, cryptocurrency wallet data, and Telegram and Discord sessions. It also gathers system information including hardware information and the external IP address and can take screenshots to better understand the environment, prior to launching the malware. All these core functions are inherited from Phemedrone Stealer.
And this is the crypto wallet that his criminals have been using,
And checking one of the Bitcoin address:
This address has transacted 303 times on the Bitcoin blockchain. It has received a total of 0.55872241 BTC $33,310.87 and has sent a total of 0.55872241 BTC $33,310.87 The current value of this address is 0.00000000 BTC $0.00.
So it means that this criminals are making money already with more than half a Bitcoin.
And they look for the follow crypto wallets,
The crypto-clipper includes 9 regex patterns for addresses across various blockchains: BTC, ETH, XMR, XLM, XRP, LTC, NEC, BCH, DASH.
https://research.checkpoint.com/2024/unmasking-styx-stealer-how-a-hackers-slip-led-to-an-intelligence-treasure-trove/So again, we need to be very careful on clicking any links that we see or some unknown emails we getting. We need to keep our software updated as well. And we should really educated ourselves because it's very crucial that we equipped ourselves with the knowledge on how to protect our machines specially if we have crypto wallets installed. We don't want to be the next victim of this criminals.