Arkanix Stealer Emerges as New Threat: Steals VPN Logins, Wi-Fi Credentials, and Screenshots
A newly discovered information-stealing malware called Arkanix is rapidly evolving to target sensitive user data, including VPN credentials, system information, and wireless network passwords. Security researchers have identified this emerging threat as…
A newly discovered information-stealing malware called Arkanix is rapidly evolving to target sensitive user data, including VPN credentials, system information, and wireless network passwords. Security researchers have identified this emerging threat as a short-lived, profit-driven malware designed for quick financial exploitation through the sale of stolen data and direct credential compromise. The threat actors behind Arkanix have demonstrated remarkable agility by releasing the malware in multiple programming languages within just a month of initial development. The malware is actively distributed through Discord channels, often masquerading as legitimate tools to deceive unsuspecting users. This distribution strategy highlights the operators’ focus on rapid monetization rather than long-term stealth and sophistication. Arkanix exists in two distinct variants: a Python-based version and a more advanced C++ implementation. The Python version is distributed using Nuitka, a Python compilation tool that converts code into self-contained executables. Nuitka packaged loader. Upon execution, it extracts a Python environment and runs the malicious payload from memory, fetching additional code from the command-and-control server at arkanix.pw. The C++ variant is offered as a “Premium” option on the threat actors’ web panel, alongside additional premium features for stealing VPN accounts and Steam credentials. Access to the Arkanix web panel requires an invite code distributed through Discord, where operators manage customer accounts and collect stolen data. This infrastructure demonstrates organized criminal operations designed to attract paying customers while maintaining operational security through invitation-only access. Extensive Stealing Capabilities The malware supports data extraction from a wide variety of Chromium-based browsers, including Chrome, Edge, Opera, Vivaldi, Tor, and Yandex. Victims’ sensitive information is compromised through browser extension data collection, particularly crypto wallets like MetaMask, Binance, and Exodus. The stealer also harvests wallet information from dedicated applications including Electrum and Ethereum wallets. Notably, Arkanix steals Wi-Fi credentials by executing the ‘netsh wlan show profiles’ command, extracting clear-text passwords stored in Windows profiles. VPN account details are harvested from popular services including NordVPN, ExpressVPN, ProtonVPN, and Mullvad. Configuration options. The malware captures comprehensive system information including CPU and GPU specifications, installed antivirus software, and timezone data information valuable for reconnaissance and targeted attacks. The C++ variant employs sophisticated evasion techniques, specifically targeting Chrome’s App Bound Encryption (ABE) introduced in version 127. To bypass this security mechanism, the malware utilizes “Chrome Elevator,” a post-exploitation tool that injects malicious code directly into the Chrome browser process. Implications for Users By executing within the browser’s context, the injected code can decrypt protected credentials without triggering ABE’s identity verification system. The C++ version also extracts Remote Desktop Protocol (RDP) credentials from .RDP files, providing attackers with additional lateral movement capabilities. Threat actors apply VMProtect obfuscation to all payloads, adding another layer of detection evasion.The rapid development of Arkanix variants and feature expansion demonstrates the threat actors’ technical expertise and commitment to monetization. Users should exercise extreme caution with downloads from Discord and untrusted sources, ensure their browsers and operating systems are fully patched, and consider using password managers with encryption-focused design. Organizations should implement endpoint detection and response (EDR) solutions capable of identifying suspicious process injection and memory execution activities. Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Based on reporting by GBHackers.
The malware is actively distributed through Discord channels, often masquerading as legitimate tools to deceive unsuspecting users.
