Typhon Stealer
Aliases: Typhon Reborn V2
- First seen
- 2021-06-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-05-31 02:18:55
- Profile updated
- 2026-07-07 15:23:39
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
According to PCrisk, Typhon is a stealer-type malware written in the C# programming language. Newer versions of this program are called Typhon Reborn (TyphonReborn). Malware within this classification is designed to extract data from infected systems. The older variants of Typhon have a broader range of functionalities, while Typhon Reborn versions are streamlined stealers.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Typhon_Reborn_Stealer (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Typhon Stealer (report)
- Cisco Talos — Typhon Reborn V2 Features Enhanced Anti Analysis (report)