Mystic Stealer
- First seen
- 2023-04-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:12:59
Context
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants. Mystic implements a custom binary protocol that is encrypted with RC4.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Mystic Stealer (report)
- zscaler.com — Mystic Stealer (report)