Phemedrone Stealer

Aliases: Ov3r_Stealer

First seen
2022-05-10 00:00:00
Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-21 04:43:38
Profile updated
2026-07-07 14:54:58

Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical

Context

Phemedrone Stealer, also known as Ov3r_Stealer, is a credential-stealing malware family targeting sensitive information across various industries. It is designed to exfiltrate credentials and have been observed in attacks on multiple sectors including financial services and telecommunications.

Exploited vulnerabilities

  • CVE-2023-36025 (vulnerability)

Reports & references

  • thehackernews.com — Beware Fake Facebook Job Ads Spreading (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Phemedrone Stealer (report)
  • spycloud.com — Phemedrone Stealer (report)
  • Trend Micro — Cve 2023 36025 Exploited For Defense Evasion In Phemedrone Steal (report)
  • splunk.com — Unveiling Phemedrone Stealer Threat Analysis And Detections (report)
  • github.com — Readme.Md (report)
  • blog.dexpose.io — Anydesk Clone Drops Net Loader With Aes Encrypted Payload And Av Evasion Delivering Phemedrone Stealer (report)
  • trustwave.com — Facebook Ad Spreads Novel Malware (report)

External references