New Malware Styx Stealer Targets Windows Users, Steals Credentials

17 Aug 2024

An alarming report from Check Point Research, published today and detailed first here on Forbes, warns that a powerful new attack from a known threat actor is now underway. Targeting Windows users, this “malicious” new malware will steal anything it can find—including browser cookies, security credentials, and instant messages. The underlying malware has been seen before, but this latest iteration has been enhanced to be much better at emptying crypto wallets.

Overview of the Threat

The malware is an adaptation of the Phemedrone Stealer which made headlines earlier this year. Exploiting a vulnerability in Microsoft Windows Defender, the software executes scripts on PCs without prompting any security warnings.

Microsoft patched CVE-2023-36025 last year, and users can protect themselves by ensuring their operating system is up-to-date. However, with hundreds of millions of Windows 10 users facing the impending end of support in October 2025, many without the capability to upgrade to Windows 11 or the financial means to purchase a new device, the potential for exploitation is significantly heightened.

Check Point identifies this new malware variant, dubbed Styx Stealer, as being linked to one of the Agent Tesla threat actors, known as Fucosreal. Agent Tesla is a Windows Remote Access Trojan (RAT) typically offered as Malware-As-A-Service (MaaS). Once a PC is compromised, it opens the door for more dangerous software installations, often leading to ransomware attacks.

Accessibility and Functionality

Styx Stealer is available for rent at $50 per month, with a lifetime license priced at $500. Check Point has noted that “the website selling Styx Stealer is still active, and anyone can purchase it.” The creator of Styx Stealer remains active on Telegram, responding to inquiries and reportedly working on a second product, Styx Crypter, designed to bypass antivirus protections. Consequently, Styx Stealer continues to pose a significant threat to users globally.

While Styx Stealer exploits a Windows vulnerability to infect systems, it also capitalizes on other security weaknesses, including the theft of session cookies, which enable a threat actor to replicate secure logins on their own machines. Google Chrome is the primary target for such thefts, given its extensive user base. In response, Google is implementing measures to link session cookies to specific device IDs, effectively shutting down the vulnerability. Furthermore, Google is encrypting and binding cookie data to specific applications, mitigating the risk of unauthorized access through malware-enabled rogue logins.

However, the threat is not limited to Chrome. Check Point indicates that Styx Stealer targets all Chromium-based browsers, including Edge, Opera, and Yandex, as well as Gecko-based alternatives like Firefox, Tor Browser, and SeaMonkey.

Innovative Crypto Theft Techniques

New elements introduced in this malware enhance its capabilities for crypto theft. Check Point explains that “crypto-stealing through crypto-clipping is a new functionality absent in Phemedrone Stealer, which operates autonomously without a command and control server while the malware is installed on the victim’s machine.” This allows Styx Stealer to quietly siphon cryptocurrency in the background.

Styx Stealer continuously monitors the clipboard at configurable intervals (defaulting to two milliseconds). If it detects a change, it triggers a crypto-clipper function that steals cryptocurrency during transactions by substituting the original wallet address with that of the attacker. The crypto-clipper is equipped with nine regex patterns for addresses across various blockchains, including BTC, ETH, and XMR.

In its quest for stealth, the malware employs additional defenses to safeguard its operations. If the crypto-clipper is activated, Styx Stealer implements anti-debugging and analysis techniques, complicating efforts to detect and neutralize it.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7248488
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1657017
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
708096
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
487448
downloads

News and reviews for Desktop Windows

Adds Native Sudo to Windows 11 for Developers

Microsoft introduces a native sudo feature in Windows 11. It comes with limitations, sparking comparisons with the more mature gsudo.

Read more

Key PC Games Arriving in 2026 Across Steam

In 2026, PC games, including major and indie releases, will feature prominently on Steam, offering fresh options for North America.

Read more

Windows 11 Adds Native NVMe Driver for Faster SSD Performance

Microsoft introduces native NVMe driver on Windows 11 25H2; users experience SSD speed boosts.

Read more

New Game+ Showcase Highlights Indie Releases and Announcements

The New Game+ Showcase on 2024-01-08 spotlighted new Xbox and PC games, including Atomic Heart 2 and Beautiful Light, fueling gaming excitement.

Read more

Igrosoft Features in UK £5 Deposit Casinos

Igrosoft slot games now available at UK casinos offering £5 minimum deposits. Expect welcome bonuses and popular titles.

Read more

Enhance Windows 11 Taskbar with Windhawk Customizations

Windhawk tool enriches Windows 11 taskbar, adding customization options and themes.

Read more

Windows 11 Enhances Access with PowerToys Command Palette

PowerToys Command Palette streamlines app launching and system commands on Windows 11, enhancing user productivity.

Read more

Humble Bundle Offers 7 PC Games for $13.80, Benefits Charity

Humble Bundle's Decked Out Collection offers 7 PC games for $13.80 with proceeds going to the American Cancer Society.

Read more

Affordable Antivirus Options for Home Devices

Discover budget-friendly antivirus deals under $30 for 2026 with essential security features.

Read more

Free Script Removes AI Features from Windows 11

A new script disables AI features like Copilot in Windows 11, offering a cleaner interface.

Read more