Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

June 5, 2026

How Low Will Bitcoin Price Go After 13% Crash?

June 4, 2026

Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

June 4, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

    June 4, 2026

    Bitcoin Price Plunges Below $62,000, Erasing Months Of Gains

    June 4, 2026

    Tom Lee’s BitMine Seeks $300 Million Raise to Buy More Ethereum

    June 4, 2026

    Ethereum Crashes 60% As Analysts Dump ETH And Rotate Into These Altcoins

    June 4, 2026

    Ethereum Weakness May Be Final Phase Before Next Market Expansion

    June 4, 2026

    Ethereum’s Multi-Year Support Test Could Shape Its Next Big Move

    June 4, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026

    JPMorgan Chase CEO Speaks Out Against Clarity Act, Says Banks Will Fight Bill in Upcoming Markup

    June 4, 2026

    Bitcoin Traders Turn Most Fearful In 2 Months Following Crash

    June 4, 2026

    The Rapid XRP Growth Trajectory That Investors Should Be Aware Of

    June 4, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    Top Crypto Events to Watch This Week Across Europe and Beyond

    June 4, 2026

    Tezos Unveils TzEL, an Experimental Post‑Quantum Privacy Rollup

    June 4, 2026

    why big banks hesitate in front of blockchain

    June 4, 2026

    Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

    June 3, 2026

    Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

    May 29, 2026

    Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

    May 29, 2026

    New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

    May 28, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026
  • Web 3
    1. Gaming
    2. View All

    Pi Network Expands Gaming Ecosystem as CiDi Games Launches Developer Center

    June 3, 2026

    GMATRIXS Taps GamePad to Boost Web3 Gaming and DeFi Infrastructure

    June 3, 2026

    Code as Constitution: How Crypto Governance Is Moving Into the Real World

    June 2, 2026

    Why Toncoin Is Rising as Telegram Pushes Past Tap-to-Earn

    June 2, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

    June 4, 2026

    Blockchain Association urges Senate to pass Clarity Act with letter from 160 former security officials

    June 4, 2026

    NYDFS and EBA Sign Agreement to Collaborate on Stablecoin Regulation

    June 4, 2026

    Bank of England stablecoin caps may choke the UK’s pound-token market before launch

    June 3, 2026

    Cardano just canceled is 2026 Summit

    June 2, 2026

    Trader turns $2,480 into $12 million after holding Binance memecoin for 8 months

    June 1, 2026

    Crypto walked so banks could run

    May 30, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026
  • Analysis

    Wedbush’s Dan Ives Sees 30% Upside for ‘Mispriced’ Mag 7 Stock, Says AI Could Hit Monetization Phase in Coming Months

    June 4, 2026

    Here’s What Traders Are Watching

    June 4, 2026

    Zcash was rumored to have stopped working

    June 4, 2026

    Here’s Why BTC Could Fall to $54K

    June 4, 2026

    Banks pushed Congress to kill stablecoin yield with CLARITY Act

    June 4, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Mt. Gox-linked wallets moved 10,422 BTC, worth roughly $739 million as BTC price slides

    June 4, 2026

    XRP is sitting on a volatility trap as liquidity dries up and leverage builds

    May 27, 2026

    Kraken moves Bitcoin to Chainlink as bridge fears spread across DeFi

    May 16, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»New ‘Chihuahua Stealer’ Targets Browser Data and Crypto Wallets
New ‘Chihuahua Stealer' Targets Browser Data and Crypto Wallets
Security and Privacy

New ‘Chihuahua Stealer’ Targets Browser Data and Crypto Wallets

September 10, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new strain of infostealer blending standard malware techniques with unusually advanced features has been detected.

First flagged by a Reddit user in April 2025, the malware, known as Chihuahua Stealer, was analyzed by G Data CyberDefense, which shared its findings in a May 13 report.

While appearing unsophisticated on the surface, this .NET infostealer employs advanced methods, including stealthy loading, scheduled task persistence and a multi-staged payload.

Multi-Stage PowerShell Script Infection

On April 9, a user on the r/antivirus subreddit shared how they were tricked into executing an obfuscated PowerShell script from a Google Drive document.

Upon investigation, G Data CyberDefense discovered that the PowerShell-based loader triggers a complex, multi-stage execution chain that leverages Base64 encoding, hex-string obfuscation and scheduled jobs to maintain persistence.

The loader is designed to be modular and stealthy, retrieving additional payloads from fallback command-and-control (C2) domains as needed.

The multi-stage chain involves the following steps:

  1. A lightweight launcher executes a Base64-encoded PowerShell string via iex, bypassing execution policies and hiding the payload from static analysis and signature-based detection
  2. The launcher decodes and reconstructs a heavily obfuscated hex payload by removing delimiters and converting hex to ASCII, dynamically assembling the next-stage script to evade static and sandbox analysis
  3. The script establishes persistence by scheduling a job that scans for infection markers (“*.normaldaki” files) and, if present, contacts a primary (and fallback) C2 server to retrieve and execute additional payloads based on received commands
  4. The persistent job obtains a .NET assembly from a remote domain, loads a Base64-obfuscated payload (the Chihuahua Stealer) from OneDrive and executes it in-memory via reflection before cleaning up visible traces (console and clipboard)
See also  On-Chain Data Shows Why Bitcoin’s Next Stop Could Be At $82K

Chihuahua Stealer’s Execution, Encryption and Data Exfiltration

The stealer initiates execution with the DedMaxim() function, which prints transliterated Russian rap lyrics to the console with short pauses between each line. The G Data researchers believe this to be a signature, albeit serving no functional purpose.

After displaying the lyrics, the stealer executes its main logic in the PopilLina() function, where it gathers the machine name and disk serial number via Windows Management Instrumentation (WMI), then obfuscates and hashes them to generate a unique identifier for the infected system. This identifier is used to name the archive and folder that will store the exfiltrated data.

After generating a unique victim ID and preparing a staging directory, the malware begins extracting data by searching for browser and crypto wallet files in user directories.

It utilizes a function to scan dynamic paths (with %USERPROFILE% placeholders) for installed browsers, and then another function to systematically extract credentials, cookies, autofill data, browsing history, sessions, and payment information from each detected browser.

Additionally, it targets crypto wallet extensions by identifying and copying data from folders associated with known wallet extension IDs.

After extracting browser data and crypto wallet extension files, the malware gets the stolen information ready for encryption and exfiltration. It creates a plaintext file named Brutan.txt in the working directory, then compresses all stolen data into a “.chihuahua” archive. Immediately afterward, the archive is encrypted using AES-GCM.

Once the stolen data has been zipped and encrypted into a “.VZ” file, the malware attempts to exfiltrate it to an external server using a retry loop.

See also  Why is the Crypto Market Down Today Amid the End of the U.S. Government?

The actual exfiltration happens in VseLegalno(). The function creates a WebClient instance and sets headers to mimic a binary file upload, then uploads the “.VZ” encrypted file to hxxps://flowers[.]hold-me-finger[.]xyz/index2[.]php.

Finally, the stealer wipes all evidence of its activity from the disk by using standard file and directory deletion commands.

G Data’s Mitigation Recommendations

G Data CyberDefense provided a list of recommendations to mitigate the Chihuahua Stealer threat:

  • Alert on frequent scheduled PowerShell jobs with suspicious or obfuscated commands
  • Hunt for unusual file extensions or marker files in directories like Recent or Temp
  • Detect Base64 decoding combined with .NET reflection (e.g., Assembly::Load()) in PowerShell logs
  • Flag uncommon AES-GCM usage via Windows CNG APIs, especially when tied to outbound HTTPS traffic
Browser Chihuahua Crypto Data Stealer Targets wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

June 4, 2026

Top Crypto Events to Watch This Week Across Europe and Beyond

June 4, 2026

Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

June 4, 2026

Mt. Gox-linked wallets moved 10,422 BTC, worth roughly $739 million as BTC price slides

June 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

BlackRock eyes tokenized crypto ETFs and stocks – Report 

September 12, 2025

3 Altcoins Showing Silent Strength Despite Low Market Attention

November 28, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

June 5, 2026

How Low Will Bitcoin Price Go After 13% Crash?

June 4, 2026

Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

June 4, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.