Since May 2025, a new credential-stealing malware, known as Maranhão Stealer , has emerged as a significant threat to users of pirated software gaming . It is distributed via deceptive websites hosting cracked launchers and cheats, and leverages cloud hosting platforms to deliver innocent-looking trojanized installers

Upon execution, the installer unpacks a Node.js–compiled binary, embedded in an Inno Setup. It starts a discreet infection process that evades user detection while collecting sensitive data.
In its initial campaigns, malicious actors lured victims with attractive download links like DerelictSetup.zip, promising modified game content. In the background, however, the Inno Setup wrapper installs various components, including updater.exe, crypto.key, and infoprocess.exe, in a hidden “Microsoft Updater” directory under %localappdata%\Programs.
Cyble analysts noted that the malware establishes persistence via Run registry keys and scheduled tasks, immediately after deployment.
See also: Phoenix RowHammer: Bypasses advanced DDR5 memory protections
The Maranhão Stealer's impact extends beyond simple credential theft. By injecting a reflective DLL into browser processes, the malware bypasses security measures such as AppBound encryption to extract saved passwords, cookies, and browsing history from Chrome, Edge, Brave, Opera, and other Chromium-based browsers.
Cyble researchers discovered that the malware also targets cryptocurrency wallets—Electrum, Exodus, Coinomi, and others—making it a dual threat to both traditional account credentials and digital asset wallets.
In addition to collecting credentials, Maranhão Stealer performs extensive system reconnaissance . It collects hardware and network information via WMI queries, profiles the operating system, CPU, disk space, and geographic location of the infected computer.
Screenshots captured via inline C# in PowerShell further enhance data theft capabilities, allowing malicious actors to monitor user activity in real time.

Maranhão Stealer: The infection mechanism in more detail
A closer look at the infection mechanism reveals a multi-layered process designed for stealth and reliability. After executing the Inno Setup installer, the main payload (updater.exe) is launched in /VERYSILENT mode, suppressing any installation dialogs.
See also: Mustang Panda develops SnakeDisk USB Worm to distribute Yokai Backdoor
Persistence is immediately ensured with a registry modification. Once the Run key is in place, the malware marks its directory and files with hidden and system attributes via attrib +h +s (ensuring they remain hidden from casual inspection).
The next phase involves launching a helper process, infoprocess.exe, which injects a DLL payload directly into the current browser processes. Using low-level Windows APIs — NtAllocateVirtualMemory, NtWriteProcessMemory, and CreateThreadEx — the malicious module maps itself into the target's memory without touching the disk.
This reflective injection not only evades antivirus scans but also runs within legitimate browser executables, making detection even more difficult.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Combining social engineering, cloud distribution, and advanced injection tactics, Maranhão Stealer exemplifies the sophistication of modern credential stealing malware.

Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.
See also: BlackNevas Ransomware encrypts files and steals data
It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
