#NeedleStealer

Malware/Tool

2026-08-13 • From fake interview to signed ClickOnce: inside a three-payload Windows chain

NeedleStealer is a Go-based Windows information stealer delivered through a signed ClickOnce chain targeting a cryptocurrency employee. Its loader unpacked the final x64 executable in memory from a PE file disguised with a PNG extension. Enabled modules collected Chromium and Firefox credentials and sessions, browser-wallet extensions, desktop-wallet material, Telegram Desktop data, screenshots, and host inventory. The malware handles Chromium App-Bound Encryption, Windows DPAPI, Firefox NSS decryption, Chrome DevTools Protocol collection, ZIP staging, file upload, and campaign-specific build identification, and communicates with a configured HTTPS backend.

Tagged Reports

« Back