OCTALYN STEALER UNMASKED

July 16, 2025, 8:18 a.m.

Description

The Octalyn Forensic Toolkit, a publicly available GitHub project, presents itself as a research tool but functions as a sophisticated credential stealer. It consists of a C++ payload module and a Delphi-based builder interface, allowing even low-skilled actors to generate functional binaries. The toolkit extracts browser data, Discord and Telegram tokens, VPN configurations, gaming account data, and cryptocurrency wallet artifacts. It establishes persistence, organizes stolen data, and exfiltrates it via Telegram. The malware's modular design, ease of use, and active exfiltration capability pose significant risks if misused. It employs obfuscation techniques, Windows persistence methods, and structured data theft, demonstrating a deliberate effort to evade detection and maximize impact.

Date

  • Created: July 16, 2025, 8:06 a.m.
  • Published: July 16, 2025, 8:06 a.m.
  • Modified: July 16, 2025, 8:18 a.m.

Indicators

  • cea94fd48ef98f6e9db120cdb33fa1099846ebcf9e6d6f8de3b53250d2087f0a
  • abe96669d90f52529b5dad847f43961a4b8b56c3893f6233a404b688c5a6069e
  • 8bd9925f7b7663ca2fcb305870248bd5de0c684342c364c24ef24bffbcdecd8b
  • 8bb868a4bd9ed5e540c3d6717b0baa1cd831fc520ee02889bc55e2aac66d9d34
  • 8af7fc21bc9c13d877f598886f363a4c7c1105bcda18e17db74d7e1584a9cae2
  • 44778cf0de10af616ef2d8a5cc5048f7cf0faa204563eab590a1a9ea4a168ef7
  • 3b3a096a9c507529919f92154f682490fa8e135f3460549a917cf23113a7b828

Attack Patterns