Koi Stealer

First seen
2023-02-01 00:00:00
Malware type
credential-stealer, trojan
Last IoC activity
2026-07-12 01:01:17
Profile updated
2026-07-07 15:00:46

Targeted industries: financial-services technology-and-telecommunications

Context

Koi Stealer is a trojan designed to capture and exfiltrate sensitive information, primarily targeting credentials from browsers and other applications. It is often distributed via phishing campaigns and has been observed targeting various industries with a focus on stealing financial and personal data.

Reports & references

  • medium.com — Updates From The Maas New Threats Delivered Through Nullmixer D45Defc260D1 (report)
  • esentire.com — Unraveling Not Azorult But Koi Loader A Precursor To Koi Stealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Koistealer (report)

External references