Poulight Stealer
Aliases: Poullight
- First seen
- 2019-06-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 01:06:53
- Profile updated
- 2026-07-07 15:16:05
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Poulight Stealer, also known as Poullight, is an information-stealing malware designed to exfiltrate sensitive data, including credentials, from compromised systems. It is mainly propagated through phishing campaigns and is known to target various industries to extract valuable information.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Poullight (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Poulight Stealer (report)
- twitter.com — 1240389621638402049 (report)
- youtube.com — Watch (report)
- blog.360totalsecurity.com — A Txt File Can Steal All Your Secrets (report)
- carbonblack.com — Tau Threat Discovery Cryptocurrency Clipper Malware Evolves (report)