Koi Stealer
- First seen
- 2023-02-01 00:00:00
- Malware type
- credential-stealer, trojan
- Last IoC activity
- 2026-07-12 01:01:17
- Profile updated
- 2026-07-07 15:00:46
Targeted industries: financial-services technology-and-telecommunications
Context
Koi Stealer is a trojan designed to capture and exfiltrate sensitive information, primarily targeting credentials from browsers and other applications. It is often distributed via phishing campaigns and has been observed targeting various industries with a focus on stealing financial and personal data.
Reports & references
- medium.com — Updates From The Maas New Threats Delivered Through Nullmixer D45Defc260D1 (report)
- esentire.com — Unraveling Not Azorult But Koi Loader A Precursor To Koi Stealer (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Koistealer (report)