Arkanix Stealer: Newly discovered short term profit malware
Dec. 21, 2025, 6:18 p.m.
Description
A new information stealer named Arkanix has emerged, likely designed for short-term financial gains. Advertised on Discord, it has rapidly evolved from a Python-based to a C++ version. The malware steals data from various browsers, crypto wallets, VPN accounts, and system information. It employs sophisticated techniques like VMProtect for obfuscation and 'Chrome Elevator' to bypass App Bound Encryption. Arkanix is distributed through Discord and online forums, disguised as legitimate tools. The threat actors offer a web panel with premium features, including VPN and Steam account theft. This case highlights the ease of starting cybercrime businesses for quick profits, with actors demonstrating considerable experience in malware development and distribution.
Tags
Date
- Created: Dec. 1, 2025, 7:55 p.m.
- Published: Dec. 1, 2025, 7:55 p.m.
- Modified: Dec. 21, 2025, 6:18 p.m.
Indicators
- 6960d27fea1f5b28565cd240977b531cc8a195188fc81fa24c924da4f59a1389
- 6ea644285d7d24e09689ef46a9e131483b6763bc14f336060afaeffe37e4beb5
Additional Informations
- arkanix.pw