WRECKSTEEL

Malware type
credential-stealer, screen-capture
Family
Malware family
Profile updated
2026-07-07 13:15:58

Context

According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.

Reports & references

  • CERT-UA — 6282902 (report)
  • socprime.com — Detect Uac 0219 Attacks Against Ukrainian State Bodies (report)
  • cip.gov.ua — Novi Kiberzagrozi Kogo I Yak Atakuyut Vorozhi Ugrupovannya (report)
  • securityaffairs.com — Ukraine Sees Surge In Ai Powered Cyberattacks By Russia Linked Threat Actors (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Wrecksteel (report)
  • cip.gov.ua — Download (report)

External references