According to researchers, a new trojan, called Masad Stealer , and is used to monitor victims' systems and steal data.
Masad Stealer uses Telegram as a command and control channel in order to maintain anonymity and hide malicious activity.
Telegram is often used by dangerous hackers to carry out attacks.
Masad Stealer has been advertised on underground hacking forums as spyware that has the ability to steal data browser and, usernames, passwords , credit information card
The malicious campaign using Masad Stealer is currently targeting thousands of victims around the world. Researchers believe it will cause a lot of problems
“This malware is advertised on various hack forums as Masad Stealer. It starts with a free version and continues with versions that ask for up to $85. Each version of the malware offers different features.”

Masad Stealer: Infection
The administrators of Masad Stealer use Autoit script to write the malware and later convert it into a Windows. If users run it, the malware will be installed in %APPDATA%\folder_name} {file_name}.
Once installed, it begins collecting the following sensitive information:
- Cryptocurrency Wallets
- Information about computers and systems
- Credit card details
- Browser data
- Browser cookies
- Access codes
- Software
- Desktop screenshots
- Files from the desktop
- Steam files
- Discord and Telegram data
- FileZilla files
The administrators of Masad Stealer use various methods to distribute the malware.
A researcher mentioned various legitimate software, such as CCleaner.exe, Iobit v 1.7.exe, Whoami.exe, Galaxy Software Update.exe, which the malware imitates to trick users into installing it.
