CollectorGoomba
Aliases: Collector Stealer
- First seen
- 2023-04-15 00:00:00
- Malware type
- credential-stealer
- Last IoC activity
- 2026-07-22 00:34:51
- Profile updated
- 2026-07-07 14:54:09
Targeted industries: financial-services technology-and-telecommunications
Context
CollectorGoomba, also known as Collector Stealer, is an information-stealing malware primarily focused on harvesting credentials from compromised systems. It has been observed targeting the financial and technology sectors without specific geographical preferences.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Collectorgoomba_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Collectorgoomba (report)
- vmray.com — Cutting Off Command And Control Infrastructure Collectorgoomba Threat Bulletin (report)
- blog.bushidotoken.net — Detecting And Fingerprinting (report)