#NeedleStealer
Malware/Tool
2026-08-13 • From fake interview to signed ClickOnce: inside a three-payload Windows chain
NeedleStealer is a Go-based Windows information stealer delivered through a signed ClickOnce chain targeting a cryptocurrency employee. Its loader unpacked the final x64 executable in memory from a PE file disguised with a PNG extension. Enabled modules collected Chromium and Firefox credentials and sessions, browser-wallet extensions, desktop-wallet material, Telegram Desktop data, screenshots, and host inventory. The malware handles Chromium App-Bound Encryption, Windows DPAPI, Firefox NSS decryption, Chrome DevTools Protocol collection, ZIP staging, file upload, and campaign-specific build identification, and communicates with a configured HTTPS backend.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days