Phemedrone Stealer is an information-stealing malware first documented in early 2023 by analysts at Trend Micro and the Sekoia TDR team. It belongs to the infostealer category, targeting credentials, browser data, cryptocurrency wallets, and system information from infected Windows machines. The malware is operated by a financially motivated threat actor tracked as “Terminator” or “Phemedrone Team,” selling the stealer as a commodity on underground forums for a one-time fee starting at $100.
Phemedrone Stealer is written in .NET/C# and uses DLL side-loading via a legitimate signed binary (e.g., mshta.exe or rundll32.exe) to bypass user account control. It propagates primarily through phishing emails containing weaponized Office documents or RAR archives, as well as through fake software cracks on torrent sites. The malware establishes C2 communication over HTTPS using a hardcoded panel URL, often hosted on compromised WordPress sites, and exfiltrates stolen data via HTTP POST requests. Persistence is achieved through a scheduled task or registry run key, and evasion includes anti-VM checks (detecting VirtualBox, VMware, sandboxes) and string obfuscation using Base64 and XOR encryption. It also disables Windows Defender via PowerShell commands before executing the payload.
First observed in January 2023, Phemedrone Stealer was notably used in a widespread campaign targeting European cryptocurrency exchanges in March 2023, stealing over $500,000 in digital assets from victims in Germany and the Netherlands. The malware is associated with the exploitation of CVE-2023-36025 (a Windows SmartScreen bypass patched in November 2023) to deliver its payload without user warnings. In April 2024, the Ukrainian Cyber Police arrested two individuals linked to distributing Phemedrone Stealer via fake Telegram bots, seizing servers used for C2 infrastructure.
Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Sekoia’s public repository). Behavioral indicators include creation of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunPhemedrone and outbound connections to domains like phemedrone[.]cc and checkup[.]host. The User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36” is used for C2 traffic. Mutex name GlobalPhemedroneMutex prevents multiple instances.
Phemedrone Stealer poses a high risk to individual users and small businesses, causing credential theft, financial loss from drained cryptocurrency wallets, and identity theft through exfiltrated session cookies. The malware primarily targets the cryptocurrency, gaming, and e-commerce sectors, with a 2023 Sekoia report estimating over 10,000 infections globally within its first six months of activity. Affected users often face account takeovers on platforms like Discord, Steam, and Coinbase.
Apply Microsoft’s CVE-2023-36025 patch, enable application control via Windows Defender Application Guard, and deploy YARA rules from Trend Micro’s “Phemedrone Stealer Detection” advisory. Block known C2 domains (e.g., phemedrone[.]cc) at the network perimeter and use endpoint detection and response (EDR) tools to flag PowerShell spawning from Office applications or scheduled tasks named “SystemUpdate.”
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.