APT / THREAT GROUP
KleptoParasite Stealer
4
aliases
Last seen:Mar 17, 2026
Intelligence Profile
KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer. It is modular and comes with a IP retriever module, a Outlook stealer (32bit/64bit) and a Chrome/Firefox stealer (32bit/64bit). Earlier versions come bundled (loader plus modules), newer versions come with a loader (167k) that grabs the modules.
PDB-strings suggest a relationship to JogLog v6 and v7.
Threat Analysis
KleptoParasite Stealer is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
External References
Quick Facts
TypeAPT / Threat Group
Aliases4
Also Known As
KleptoParasite StealerParasitewin.kleptoparasite_stealerJoglog
External Intelligence
Malpedia: win.kleptoparasite_stealerResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.