Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MicroStealer

85
Global rank
81 infographic chevron month
Month rank
59 infographic chevron week
Week rank
0
IOCs

MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.

Stealer
Type
Unknown
Origin
1 December, 2025
First seen
14 August, 2026
Last seen

How to analyze MicroStealer with ANY.RUN

Type
Unknown
Origin
1 December, 2025
First seen
14 August, 2026
Last seen

IOCs

IP addresses
2.16.241.218
2.16.241.205
23.52.181.141
216.198.79.1
48.209.133.15
150.171.109.193
74.179.77.204
40.126.32.68
23.216.77.28
95.100.102.101
142.251.14.113
150.171.22.17
150.171.28.11
48.192.1.65
23.11.41.157
131.253.33.203
150.171.27.11
104.18.22.222
172.211.123.250
74.178.240.51
Hashes
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
f9e4da319fe1f5a7d497c452421f4648a24ec7588f309ebea0f0cd61a6251eef
d988156066b7fd22de278fbc96759d2caea6552094ffeb2ddd9307806059c5e4
8b2e057387e9714efef3580a36459acf56aab53c806cd7d7dbb6e17cef977ef9
867a31befa91e9aa232b5edcfa3688230e4d77e4f8f63f782f20017aca9a6343
14bf8af0ec00ec4d1b1c48ed250d95f1917a05b4480866a0f0d3e6575f2fb0ba
fd633e1828be5b8a22b27d7d61655cbabd1769b041a76eda5545091cc672bca1
34f3d13e671204edd7c8324b40eb7070919c6c67e0e9aaf5d2f8bad5fab09ca7
fbeb1790218a24ac41e8c2e5bfa278508a345cef2e67be7fc2ddd9464ce8a4b2
4e987457f6e0b88119955bff45499d74bc9102631e01e3cad4b9fdcaed4d2f2e
ae0140c26ae95539091f4d4ed9bf99bfe871f02f71d5526d0e156d20b7f18a01
49a6af676b2133a16df0825aa3efa29c4e60d3e0399003ab86ec8a8147273f8a
6ee966926c812be209a7f0db5b7fa51877af46fe02eca2a104b3c498f7a4cb36
39264c00acb42118f46af4f8d088566ec6ef0b7e7dd9cf016336e1a0b1c631ea
59db6fd8d1d9bad9e73f0afbfb3a029ef27a8617074bfeb5f25ff8054078572b
04e5fa94cad76062bb4be8dd15dc3938ff14bc5e04a836e3f6e8bdaacf7e0e9d
ea718425a21da6a90f8e9af98fad5f875ea518a1549fb568a62b9683391d8e9b
c01e639c938fec3f7f831427ce59fa784f16668e651a4cd6bdb13e4ff547dedf
Domains
edge.microsoft.com
ocsp.digicert.com
copilot.microsoft.com
www.microsoft.com
th.bing.com
www.bing.com
settings-win.data.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
go.microsoft.com
slscr.update.microsoft.com
google.com
slumpcute.com
config.edge.skype.com
activation-v2.sls.microsoft.com
oneocsp.microsoft.com
crl.microsoft.com
edge-consumer-static.azureedge.net
api.edgeoffer.microsoft.com
update.googleapis.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:mbfhn1g1iyp93zy3vwdrhvpztd5l-xpxzqw11x1f-rk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://slumpcute.com/
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://slumpcute.com/
https://slumpcute.com/favicon.ico
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d238%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:vri9vvh34dlurm8kzo9nugfe-t9ybvyjuf-cumutuau&cup2hreq=7c25c7cdd96941e8620020a5d80fca0f9c8ffbcb6db44ca2c0583fd2fb867c61
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 8758
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 4233
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 38890
comments 0

MicroStealer Explained: A Lightweight Malware with Heavy Business Impact

Key Takeaways

  1. MicroStealer uses a layered NSIS → Electron → Java chain for evasion and rapid spread.
  2. It steals more than passwords, focusing on browser sessions, cookies, screenshots, and wallets for immediate impact.
  3. Education and telecom sectors show heightened exposure; gaming lures expand reach.
  4. Low AV detection + redundant exfiltration (Discord + C2) enable quick, reliable data theft.
  5. Session hijacking turns endpoint compromise into persistent enterprise access.
  6. Behavior-based sandbox analysis is essential for early detection of emerging stealers.
  7. Proactively defend with ANY.RUN's Threat Intelligence Lookup for instant IOC/variant hunting and Threat Intelligence Feeds for real-time campaign visibility and automated protection — empowering SOCs to stop MicroStealer before it strikes.

threatName:"microstealer".

Malware overview in TI Lookup Malware overview in TI Lookup: landscape, IOCs, and more

What is MicroStealer Malware?

MicroStealer is an emerging infostealer malware that quietly targets browser credentials, session cookies, desktop screenshots, and cryptocurrency wallet files; all while evading traditional signature-based detection. First observed in December 2025, it gained rapid traction in sandbox environments within weeks of appearing in the wild, yet many security vendors still failed to flag it.

Its deceptively sophisticated architecture — wrapping a Java-based payload inside an Electron application inside an NSIS installer — makes it harder to analyze statically and gives it an edge during the critical early window of a campaign.

MicroStealer is not just another entry in a crowded field: it represents a new wave of professionally engineered infostealers designed to infiltrate corporate environments and exfiltrate identity data before defenders even know to look.

ANY.RUN’s Interactive Sandbox detects MicroStealer and lets observe the attack chain in its secure environment.

View sandbox analysis

MicroStealer analysis in Interactive Sandbox MicroStealer detonated in Interactive Sandbox

The malware's Node.js component is heavily obfuscated using LZ-String UTF-16 compression, compressed string arrays with numeric indices, flattened control flow, and dead code padding. Before executing its main payload, MicroStealer checks the runtime environment for processes and services commonly associated with virtual machines — if detected, execution terminates immediately, a classic anti-analysis technique.

Once running, the stealer collects:

  • Browser credentials, cookies, and session tokens from Chromium and other popular browsers;
  • Desktop screenshots;
  • Cryptocurrency wallet files;
  • Discord and Steam account profile data (used for reconnaissance and target prioritization).

All collected data is archived and exfiltrated through two simultaneous channels: Discord webhooks and attacker-controlled exfiltration servers. Using dual channels is a resilience strategy: if one endpoint is taken down, the other ensures the stolen data still reaches the threat actor.

The malware's own User-Agent header during its initial connection to Discord reads: MicroStealer/1.0 — an unusually transparent self-identification that serves as a reliable network-level detection signature for defenders who know to look.

For detailed static analysis of MicroStealer sample performed by ANY.RUN's team, explore the article in the corporate blog.

How MicroStealer Threatens Businesses and Organizations

MicroStealer poses significant risks beyond individual data theft:

  • Credential and Session Compromise: Steals browser-stored logins and active sessions for SaaS platforms, VPNs, cloud services, and corporate portals, enabling lateral movement and privilege escalation.

  • Persistent Stealth Access: Session hijacking blends malicious activity with legitimate traffic, prolonging undetected presence.

  • Business Email Compromise (BEC): Attackers gain control of corporate email, enabling fraud, invoice manipulation, and executive impersonation.

  • Data Exfiltration and Reckon: Quickly sends screenshots, profiles (e.g., Discord, Steam), and sensitive files, supporting targeted follow-on attacks or sale on underground markets.

  • Ransomware Gateway: Stolen initial access often feeds broader intrusions, BEC, or supply-chain attacks.

  • Compliance and Reputational Damage: Exposure of corporate identities risks regulatory violations and loss of trust.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

Analysis of MicroStealer submissions to the ANY.RUN sandbox shows that about 50% of observed sample uploads originated from the United States and Germany, indicating focused activity in these two major economies. The education and telecommunications sectors have shown the most elevated exposure among confirmed cases.

Industry risk profiles based on observed targeting and structural vulnerabilities Industry risk profiles based on observed targeting and structural vulnerabilities

Evolution of MicroStealer & Notable Activity

MicroStealer reflects a broader trend: infostealers evolving from simple credential grabbers into access brokers’ tools.

Key evolutionary traits:

  • Shift from file-based payloads to loader-based delivery;
  • Increased use of encryption and obfuscation;
  • Integration with underground marketplaces for data resale;
  • Faster exfiltration cycles to reduce detection windows.

While MicroStealer itself may appear under different names or variants, its behavior aligns with modern MaaS (Malware-as-a-Service) ecosystems.

How Does MicroStealer Get In the System and Spread?

Common vectors:

  • Compromised or Impersonated Accounts: Social engineering via trusted-looking messages or posts.

  • Malicious Downloads: Fake "Game Launcher" or software installers from attacker-controlled or compromised sites (e.g., Dropbox-hosted payloads, Discord CDN).

  • Phishing/Malvertising: Lures promising games, tools, or updates.

  • Drive-by or Trojanized Software: Especially in gaming/piracy ecosystems.

Once the victim runs the downloaded installer (RocobeSetup.exe), the NSIS installer silently deploys the Electron application and a UAC prompt is presented under the guise of a normal "Game Launcher" installation process — a social engineering layer built directly into the technical chain. MicroStealer does not use vulnerability exploitation for initial access; it relies entirely on the user making a trust-based decision to run the file.

How MicroStealer Malware Functions

MicroStealer's full execution chain can be broken into four distinct stages:

Stage 1: NSIS Installer (RocobeSetup.exe). The outer wrapper is a standard NSIS archive installer. It contains the Electron application, ASAR archives (app.asar and app.asar.unpacked), and the main payload — a JAR file accompanied by a bundled Java Runtime Environment — packaged inside module.zip.

Stage 2: Electron Application (Game Launcher.exe). The Electron app requests administrator privileges through a UAC dialog. Once elevated, it unpacks the bundled JRE and JAR file, placing them in %LOCALAPPDATA%. The Java executable is renamed miicrosoft[.]exe (a typosquat on the legitimate Microsoft name) to blend in with system processes during casual inspection.

Stage 3: Node.js Launcher (index.js inside app.asar). A heavily obfuscated Node.js script handles the extraction and launch of the JAR payload. Strings within the script are compressed using the LZ-String library's UTF-16 encoding and stored in a single Unicode variable, then split by a pipe delimiter and retrieved by numeric index. After extracting and deobfuscating this logic, the script resolves to a straightforward spawn() call that launches miicrosoft.exe -jar soft.jar in a detached, background process and then immediately terminates itself — ensuring the payload runs independently.

Stage 4: Java Payload (soft.jar). This is MicroStealer's core. The JAR file executes the actual credential-harvesting logic. Before beginning collection, it checks the execution environment against a list of processes and services associated with virtual machines; if a match is found, it exits. Otherwise, it:

  • Harvests credentials, cookies, and session tokens from browser profile directories;
  • Captures desktop screenshots;
  • Collects cryptocurrency wallet files;
  • Gathers Discord and Steam account data for reconnaissance;
  • Archives all collected data.

Exfiltrates the archive to both a Discord webhook endpoint and a freshly registered attacker-controlled server, using the User-Agent string MicroStealer/1.0

The dual-destination exfiltration design ensures redundancy: if either the Discord webhook or the custom server becomes unavailable or is taken down, the other still delivers the stolen data. The use of newly registered domains for the secondary exfiltration endpoint also means these domains carry no historical threat reputation at the time of the attack, further evading domain-reputation-based network defenses.

How Businesses Can Proactively Protect Against MicroStealer

The core challenge MicroStealer poses is detection lag: it spreads and exfiltrates data while antivirus signatures haven't caught up yet. This is where proactive threat intelligence — specifically ANY.RUN's TI Feeds and TI Lookup — provides a decisive defensive advantage.

ANY.RUN TI Lookup: Instant Contextual Investigation

Query TI Lookup for the threat name to instantly surface all related sandbox sessions, associated indicators, behavioral data, and attack chain details.

MicroStealer sandbox analyses found via TI Lookup MicroStealer sandbox analyses found via TI Lookup

TI Lookup allows pivoting from a single suspicious indicator to a full picture of the threat: which domains were contacted, what files were dropped, which MITRE ATT&CK techniques were used, and how similar samples have behaved across prior investigations. This transforms a vague alert into actionable, scoped threat intelligence within minutes.

domainName:"swordfull.info"

MicroStealer domain, IOCs, files, events MicroStealer domain, IOCs, files, events

TI Lookup also supports industry and geographic threat landscape filtering, allowing security teams to assess whether a threat like MicroStealer is actively targeting their specific sector or region before committing investigation resources, enabling smarter alert prioritization.

ANY.RUN TI Feeds: Continuous IOC Delivery to Your Security Stack

Threat Intelligence Feeds provide a continuously updated stream of indicators of compromise (malicious IPs, domains, URLs) derived from real sandbox analysis sessions run by over 600,000 security researchers and analysts across more than 15,000 organizations. IOCs are delivered in STIX/TAXII format for direct integration with SIEM platforms, EDR systems, IDS/IPS, and threat intelligence platforms such as OpenCTI, ThreatConnect, and ThreatQ.

TI Feeds integration options TI Feeds integration options

Because MicroStealer relies heavily on fresh infrastructure (newly registered domains with no historical reputation), real-time feed delivery is specifically valuable against this threat. Every IOC in TI Feeds is accompanied by a full sandbox report: process trees, network traffic maps, MITRE ATT&CK technique mappings, and behavioral evidence — giving SOC analysts the context they need to act rather than just a raw indicator to block.

Additional Measures:

  • Robust endpoint detection with behavior-based analysis (sandboxing).

  • Browser security (e.g., session isolation, no saved credentials where possible).

  • MFA with hardware keys or phishing-resistant methods.

  • Least privilege, network segmentation, and regular credential rotation.

  • Email/web filtering and application allowlisting.

  • Monitor for anomalous Discord/webhook traffic or unusual Java/Electron processes.

  • Awareness training on social engineering and suspicious downloads.

MicroStealer Sandbox Analysis: Confirm Behavior Instead of Guessing

New malware families like MicroStealer often lack clear static signatures or reliable reputation data, which slows down traditional investigation workflows.

Instead of relying only on static verdicts, analysts can quickly confirm what a suspicious file actually does by executing it in a controlled environment.

Running the sample in the ANY.RUN interactive sandbox reveals the full execution chain, including:

  • NSIS installer delivering the payload;
  • Electron loader extracting the JAR module;
  • Java stealer executing its data collection logic;
  • Attempts to steal browser credentials and wallet data;
  • Communication with Discord webhooks and external servers.

View sandbox analysis

MicroStealer analysis in Interactive Sandbox MicroStealer detonated in Interactive Sandbox

Within minutes, analysts can observe the complete attack chain, extract reliable IOCs, and determine whether the sample poses a real threat.

MicroStealer IOCs in Interactive Sandbox MicroStealer IOCs in Interactive Sandbox

For SOC teams, this replaces guesswork with behavior-based evidence, helping reduce investigation time and avoid unnecessary escalations.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

MicroStealer exemplifies the evolving infostealer threat: fast, evasive, and focused on high-value corporate identities. Its multi-stage design and session-stealing focus make traditional defenses insufficient. Organizations must combine proactive threat intelligence, behavioral detection, and human-centric security to stay ahead. Early visibility into such threats is key to preventing credential theft from escalating into major incidents.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More