Phemedrone Stealer
Aliases: Ov3r_Stealer
- First seen
- 2022-05-10 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:43:38
- Profile updated
- 2026-07-07 14:54:58
Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical
Context
Phemedrone Stealer, also known as Ov3r_Stealer, is a credential-stealing malware family targeting sensitive information across various industries. It is designed to exfiltrate credentials and have been observed in attacks on multiple sectors including financial services and telecommunications.
Exploited vulnerabilities
- CVE-2023-36025 (vulnerability)
Reports & references
- thehackernews.com — Beware Fake Facebook Job Ads Spreading (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Phemedrone Stealer (report)
- spycloud.com — Phemedrone Stealer (report)
- Trend Micro — Cve 2023 36025 Exploited For Defense Evasion In Phemedrone Steal (report)
- splunk.com — Unveiling Phemedrone Stealer Threat Analysis And Detections (report)
- github.com — Readme.Md (report)
- blog.dexpose.io — Anydesk Clone Drops Net Loader With Aes Encrypted Payload And Av Evasion Delivering Phemedrone Stealer (report)
- trustwave.com — Facebook Ad Spreads Novel Malware (report)