CryptBot
- First seen
- 2019-10-01 00:00:00
- Malware type
- credential-stealer, screen-capture, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 03:53:09
- Profile updated
- 2026-07-07 13:45:19
Context
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cryptbot_Auto (yara-rule)
Reports & references
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- Mandiant — Russian Targeting Gov Business (report)
- asec.ahnlab.com — 35981 (report)
- Mandiant — 1 (report)
- Mandiant — Russian Targeting Gov Business (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cryptbot (report)
- intezer.com — Cryptbot Yet Another Silly Stealer Yass (report)
- intrinsec.com — Tlp Clear Cryptbot Hunting For Intial Access Vectors (report)
- asec.ahnlab.com — 31802 (report)
- bleepingcomputer.com — Malicious Kmspico Installers Steal Your Cryptocurrency Wallets (report)
- patreon.com — Live Stream Vod 117643974 (report)
- blog.google — Continuing Our Work To Hold Cybercriminal Ecosystems Accountable (report)
- regmedia.co.uk — Handout Google Cryptbot Complaint (report)
- any.run — Cryptbot Infostealer Malware Analysis (report)
- gdatasoftware.com — 35802 Bitbucket Abused As Malware Slinger (report)
- tehtris.com — Cryptbot Downloader A Deep Cryptanalysis (report)
- research.openanalysis.net — Cryptbot (report)
- fr3d.hk — Cryptbot Too Good To Be True (report)
- cloud.google.com — Peaklight Decoding Stealthy Memory Only Malware (report)
- redcanary.com — Kmspico V5 (report)
- asec.ahnlab.com — 31683 (report)
- asec.ahnlab.com — 24423 (report)
- blogs.blackberry.com — Threat Thursday Cryptbot Infostealer (report)
- research.openanalysis.net — Cryptbot2 (report)
- asec.ahnlab.com — 26052 (report)