RisePro
- Malware type
- credential-stealer, downloader, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:32:01
- Profile updated
- 2026-07-07 13:13:42
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
RisePro is a stealer that is spread through downloaders like win.privateloader. Once executed on a system, the malware can steal credit card information, passwords, and personal data.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Risepro (yara-rule)
- MALPEDIA_Win_Risepro_Auto (yara-rule)
Reports & references
- cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
- research.checkpoint.com — Stargazers Ghost Network (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- any.run — Crackedcantil Breakdown (report)
- bitsight.com — Hunting Privateloader Malware Behind Installskey Ppi Service (report)
- embee-research.ghost.io — Identifying Risepro Panels Using Censys (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Risepro (report)
- any.run — Risepro Malware Communication Analysis (report)
- blog.sekoia.io — New Risepro Stealer Distributed By The Prominent Privateloader (report)
- gdatasoftware.com — 37885 Risepro Stealer Campaign Github (report)
- linkedin.com — Threatmon Risepro Stealer Malware Analysis Report Ugcpost 7180497665137221633 Augl (report)