Typhon Stealer

Aliases: Typhon Reborn V2

First seen
2021-06-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-05-31 02:18:55
Profile updated
2026-07-07 15:23:39

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

According to PCrisk, Typhon is a stealer-type malware written in the C# programming language. Newer versions of this program are called Typhon Reborn (TyphonReborn). Malware within this classification is designed to extract data from infected systems. The older variants of Typhon have a broader range of functionalities, while Typhon Reborn versions are streamlined stealers.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Typhon_Reborn_Stealer (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Typhon Stealer (report)
  • Cisco Talos — Typhon Reborn V2 Features Enhanced Anti Analysis (report)

External references