Predator The Thief

First seen
2018-07-01 00:00:00
Malware type
credential-stealer, spyware, keylogger
Family
Malware family
Last IoC activity
2026-07-09 10:35:20
Profile updated
2026-07-07 12:41:12

Targeted industries: financial-services technology-and-telecommunications professional-services

Context

Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • bleepingcomputer.com — Fake Microsoft Teams Updates Lead To Cobalt Strike Deployment (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • jsac.jpcert.or.jp — Jsac2020 4 Ogawa Niseki En (report)
  • secureworks.com — Gold Galleon (report)
  • cybereason.com — The Hole In The Bucket Attackers Abuse Bitbucket To Deliver An Arsenal Of Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Predator (report)
  • fortinet.com — Predator The Thief New Routes Delivery (report)
  • fumik0.com — Predator The Thief In Depth Analysis V2 3 5 (report)
  • fumik0.com — Lets Play Again With Predator The Thief (report)
  • Kaspersky — 89779 (report)

External references