📣 Send us your press release
Site updates every 15 minutes
Technology

New Katz Stealer Malware Broadly Steals User Credentials

A recently identified information-stealing malware, Katz Stealer, operating as a service (MaaS), threatens users with aggressive data collection. It can steal passwords, cryptocurrency data, and credentials from various applications.

27 July 2026
New Katz Stealer Malware Broadly Steals User Credentials
Image is an AI-generated illustration

Cybersecurity firm Picus Security has analyzed Katz Stealer, a new malware-as-a-service (MaaS) that emerged in 2025. The program is designed for extensive credential theft, targeting sensitive data across browsers, cryptocurrency wallets, messaging apps, and email clients.

The malware extracts saved passwords, cookies, and session tokens from Chromium and Firefox-based browsers. It also targets cryptocurrency wallet data from both desktop and browser extension variants. Additionally, Katz Stealer can steal tokens and session data from platforms like Discord and Telegram, and acquire credentials for email clients such as Outlook and Windows Live Mail.

Beyond common application data, Katz Stealer is capable of exfiltrating VPN, FTP, and Wi-Fi credentials. It can also capture screenshots and access clipboard contents. The broad scope of its data-stealing capabilities makes it a significant threat to user privacy and system security.

Operating under a malware-as-a-service model, Katz Stealer allows threat actors to generate customized builds and manage stolen data through a web panel. This distribution method lowers the barrier to entry for less sophisticated attackers, contributing to its rapid proliferation. Initial infection vectors typically involve phishing campaigns or malicious software downloads, often disguised within GZIP archives. The malware employs sophisticated techniques, including obfuscated JavaScript droppers and User Account Control (UAC) bypass methods, to achieve persistence and evade detection.

Original source: picussecurity.com