Sysraw Stealer
Aliases: Clipsa
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:22:06
Context
Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe". PDB strings suggest the name "Clipsa" though. First stage connects to /WPCoreLog/, the second one to /WPSecurity/. Its behavior suggest that it is an info stealer. It creates a rather large amount of files in a subdirectory (e.g. data) named "1?[-+].dat" and POSTs them.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Sysraw Stealer (report)
- decoded.avast.io — Clipsa Multipurpose Password Stealer (report)
- zerophagemalware.com — Rig Ek Via Rulan Drops An Infostealer (report)