Creal Stealer
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-18 16:45:23
- Profile updated
- 2026-07-07 14:40:02
Targeted industries: technology-and-telecommunications retail-and-hospitality media-and-entertainment financial-services
Context
Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium" version on his now-deleted Telegram channel @Crealstealer. To the day of release, it was already not FUD, but its open-source nature made it attractive for threat actors to modify the base malware and even obfuscate it for less detection ratios. The base project came with a compiler, and the general source code the compiler used was PyInstaller for compilation into native formats like exe. For C2, Discord webhooks were utilized, which in later versions got protected with a service called https://stealer.to to make deletion not possible. It Compromised following Data on Execution: * Discord Information * Browser Data * Crypto Related Data * Steam * Riot Games * Telegram * System Information * Tokens/Secrets
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Py.Creal Stealer (report)
- cyble.com — Creal New Stealer Targeting Cryptocurrency Users Via Phishing Sites (report)