WRECKSTEEL
- Malware type
- credential-stealer, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 13:15:58
Context
According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.
Reports & references
- CERT-UA — 6282902 (report)
- socprime.com — Detect Uac 0219 Attacks Against Ukrainian State Bodies (report)
- cip.gov.ua — Novi Kiberzagrozi Kogo I Yak Atakuyut Vorozhi Ugrupovannya (report)
- securityaffairs.com — Ukraine Sees Surge In Ai Powered Cyberattacks By Russia Linked Threat Actors (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Wrecksteel (report)
- cip.gov.ua — Download (report)