Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

“PupkinStealer” – .NET Malware Steals Browser Data and Exfiltrates via Telegram

A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals and enterprises. Developed in C# using the .NET framework, this 32-bit GUI-based Windows executable targets sensitive user data with a focused…

A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals and enterprises. Developed in C# using the .NET framework, this 32-bit GUI-based Windows executable targets sensitive user data with a focused and efficient approach. First observed in April 2025, PupkinStealer is designed to harvest a specific range of data, including browser credentials, personal files from desktops, session information from messaging platforms like Telegram and Discord, and desktop screenshots. What makes this malware particularly insidious is its method of exfiltration, leveraging the Telegram Bot API to transmit stolen data to attacker-controlled servers with minimal traceability. Bot details: used in exfiltration A New Threat in the Cyber Landscape PupkinStealer, with a file size of 6.21 MB and identified by the MD5 hash fc99a7ef8d7a2028ce73bf42d3a95bce, operates by initiating multiple asynchronous tasks upon execution. Its Main() method, managed by the .NET Common Language Runtime (CLR), orchestrates data theft through distinct modules. One primary function targets Chromium-based browsers such as Chrome, Edge, and Opera by extracting decryption keys from Local State files and decrypting saved credentials stored in SQLite databases using AES-GCM algorithms. Main() function Additionally, it scans the victim’s desktop for files with extensions like .pdf, .txt, and .jpg, copying them to a temporary directory. The malware also exfiltrates Telegram session data by copying the ‘tdata’ folder, enabling unauthorized account access without credentials, while Discord tokens are harvested from leveldb storage using regular expressions for potential impersonation. Technical Breakdown of Malicious Operations A screenshot of the primary screen at 1920×1080 resolution is captured and, along with all collected data, compressed into a ZIP archive with embedded metadata such as username, IP address, and Security Identifier (SID). According to Cyfirma Report, this archive, often named in the format [, is then sent to a Telegram bot identified as ‘botkanalchik_bot’ using a crafted API URL, incorporating detailed system information in the caption. Attributed to a developer alias “Ardent,” as evidenced by embedded code strings, PupkinStealer lacks advanced obfuscation or persistence mechanisms, relying instead on low-profile execution to evade detection. Its use of legitimate services like Telegram for command-and-control highlights a growing trend among cybercriminals favoring anonymity and ease of use. As part of a broader landscape of modular infostealers, PupkinStealer underscores the evolving simplicity and accessibility of malware-as-a-service offerings, posing a challenge to cybersecurity defenses. Organizations are urged to implement robust endpoint security, continuous network monitoring, and user awareness training to mitigate risks associated with such threats. Indicators of Compromise (IoCs) S/NIndicatorsTypeContext1fc99a7ef8d7a2028ce73bf42d3a95bceMD5PupkinStealer.exe29309003c245f94ba4ee52098dadbaa0d0a4d83b423d76c1bfc082a1c29e0b95fSHA-256PupkinStealer.exe3 Bot/Exfiltration URL48013735771:AAE_UrTgQsAmiAsXeDN6mehD_fo3vEg-kCMTelegram Bot TokenTelegram Bot Token for exfiltration5%APPDATA%\Temp$$Username]\Grabbers\Browser\passwords.txtFile PathCollected browser credentials Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team ->

Based on reporting by GBHackers.

A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals and enterprises.
Stephen Gale · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories