XehookStealer
- First seen
- 2023-01-01 00:00:00
- Malware type
- credential-stealer, keylogger, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:57
- Profile updated
- 2026-07-07 15:26:48
Targeted industries: financial-services technology-and-telecommunications
Context
Xehook is a .NET-based malware targeting Windows systems. It collects data from Chromium and Gecko browsers, supporting over 110 cryptocurrencies and 2FA extensions. CRIL found a potential link between Xehook Stealer, Agniane, and the Cinoshi project, suggesting a progression from a free MaaS model to the development of Xehook Stealer. SmokeLoader binaries were identified as a common vector for distributing Xehook Stealer. Xehook Stealer shares code overlaps with Agniane Stealer, indicating an evolutionary relationship.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Infostealer_Win_Xehook_Str (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Xehook (report)
- cyble.com — Xehook Stealer Evolution Of Cinoshis Project Targeting Over 100 Cryptocurrencies And 2Fa Extensions (report)