Powerful MaaS On the Prowl for Credentials and Crypto Assets
July 17, 2025, 8:26 p.m.
Description
Katz Stealer is a sophisticated infostealer marketed as Malware-as-a-Service (MaaS), launched in early 2025. It features robust credential and data theft capabilities, along with modern evasion and anti-analysis techniques. The stealer targets a wide range of personal and sensitive information, including passwords, cryptocurrency keys, and browser session data. Operated through a web-based management panel, Katz Stealer allows affiliates to generate custom payloads and manage stolen data. Its infection chain involves obfuscated JavaScript droppers, steganography, and process hollowing techniques. The malware focuses heavily on browser data theft and cryptocurrency wallet targeting, with the ability to bypass some browser security measures.
Tags
Date
- Created: July 17, 2025, 7:39 p.m.
- Published: July 17, 2025, 7:39 p.m.
- Modified: July 17, 2025, 8:26 p.m.
Indicators
- c929ee54bdd45df0fa26d0e357ba554ef01159533501ec40f003a374e1e36974
- d21beddb601c2b16bbdb7934a12b822962e40d3b3f64b7f83edc763c57649bcf
- a6b736988246610da83ce17c2c15af189d3a3a4f82233e4fedfabdcbbde0cff0
- 945365891630b70db7bd0069dca9890c3894702bfeac10a788a487eb9900870f
- 85f2455dfe4edd531a7074bd3ad2b49d065b42e9caa5129a075728961767b6b7
- 8d2ba9e251d0dc9bc1d047f8d4cb36624d0288ba417c2afa48f11348454db7aa
- e73f6e1f6c28469e14a88a633aef1bc502d2dbb1d4d2dfcaaef7409b8ce6dc99
- fb2b9163e8edf104b603030cff2dc62fe23d8f158dd90ea483642fce2ceda027
- e4249cf9557799e8123e0b21b6a4be5ab8b67d56dc5bfad34a1d4e76f7fd2b19
- e345d793477abbecc2c455c8c76a925c0dfe99ec4c65b7c353e8a8c8b14da2b6
- c601721933d11254ae329b05882337db1069f81e4d04cd4550c4b4b4fe35f9cd
- b912f06cf65233b9767953ccf4e60a1a7c262ae54506b311c65f411db6f70128
- b249814a74dff9316dc29b670e1d8ed80eb941b507e206ca0dfdc4ff033b1c1f
- 96ada593d54949707437fa39628960b1c5d142a5b1cb371339acc8f86dbc7678
- 964ec70fc2fdf23f928f78c8af63ce50aff058b05787e43c034e04ea6cbe30ef
- 925e6375deaa38d978e00a73f9353a9d0df81f023ab85cf9a1dc046e403830a8
- 5dd629b610aee4ed7777e81fc5135d20f59e43b5d9cc55cdad291fcf4b9d20eb
- 2852770f459c0c6a0ecfc450b29201bd348a55fb3a7a5ecdcc9986127fdb786b
- 2798bf4fd8e2bc591f656fa107bd871451574d543882ddec3020417964d2faa9
- 25b1ec4d62c67bd51b43de181e0f7d1bda389345b8c290e35f93ccb444a2cf7a
- 22af84327cb8ecafa44b51e9499238ca2798cec38c2076b702c60c72505329cb
- fdc86a5b3d7df37a72c3272836f743747c47bfbc538f05af9ecf78547fa2e789
- d92bb6e47cb0a0bdbb51403528ccfe643a9329476af53b5a729f04a4d2139647
- 6dc8e99da68b703e86fa90a8794add87614f254f804a8d5d65927e0676107a9d
- 80.64.18.219
- 195.182.25.71
- 31.177.109.39
- 185.107.74.40
- zxczxczxczxc.twist2katz.com
- katz-panel.com
- katzstealer.com
Attack Patterns
- Katz Stealer