Predator The Thief
- First seen
- 2018-07-01 00:00:00
- Malware type
- credential-stealer, spyware, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-09 10:35:20
- Profile updated
- 2026-07-07 12:41:12
Targeted industries: financial-services technology-and-telecommunications professional-services
Context
Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- bleepingcomputer.com — Fake Microsoft Teams Updates Lead To Cobalt Strike Deployment (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- jsac.jpcert.or.jp — Jsac2020 4 Ogawa Niseki En (report)
- secureworks.com — Gold Galleon (report)
- cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Predator (report)
- fortinet.com — Predator The Thief New Routes Delivery (report)
- fumik0.com — Predator The Thief In Depth Analysis V2 3 5 (report)
- fumik0.com — Lets Play Again With Predator The Thief (report)
- Kaspersky — 89779 (report)