Raven Stealer is a powerful information-stealing that targets users of Chromium-based browsers, most notably Google Chrome.

First observed in mid-2025, it stands out due to its modular architecture and unique design, which allow it to collect sensitive information without notifying victims. It is distributed primarily through cracked software bundles and underground forums, and exploits social engineering tactics and repackaged installers to convince users to execute its malicious payload.
Once unleashed on a system, Raven Stealer begins by examining local storage paths associated with Chrome, Edge, Brave, and similar browsers to locate encryption keys and credential vaults. It then leverages Windows API calls to decrypt and extract stored passwords, cookies, autofill entries, and payment data.
See also: PureHVNC RAT leverages GitHub for source code hosting
During this phase, the malware avoids writing any data to disk by executing payload modules directly from the resource module, encrypted with ChaCha20. This in-memory execution allows Raven Stealer to evade signature-based detection and disk monitoring defenses.

Point Wild analysts found that the resource integration technique simplifies development and complicates analysis, as configuration data and modules are dynamically retrieved at runtime.
After the initial collection of credentials, Raven Stealer compiles the stolen objects into plain text files in the user’s AppData directory, organized in a folder named “RavenStealer”. The resulting files—cookies.txt, passwords.txt, and payments.txt—are prepared for export. Data transmission is done via Telegram’s Bot API: Raven Stealer embeds a user-supplied Bot Token and a Chat ID in its payload, which it retrieves from its own resource configuration.
See also: Python-based XillenStealer attacks Windows users
This integration provides attackers with a known command and control channel while bypassing many corporate network. Despite its reliance on Telegram, the malware maintains resilience against token expiration by prompting the UI builder to accept new credentials during each payload generation.
Raven Stealer: The infection mechanism in more detail
Raven Stealer's infection mechanism relies on reflective process hollowing to inject the main DLL payload into a suspended Chrome process. Upon execution, the malware locates the path to the Chrome executable and starts a new instance in a suspended state.

Point Wild analysts noted that the payload uses ChaCha20 decryption in memory to reconstruct the DLL before execution. After writing the decrypted payload to the reserved memory, the malware adjusts the thread context to point to the remote buffer and continues the thread.
See also: RaccoonO365: Microsoft & Cloudflare dismantle phishing network
This approach cloaks malicious activity under the guise of a legitimate Chrome process, reducing the likelihood of detection. Once injected, the DLL checks browser profiles, decrypts stored credentials using the AES key found in Chrome's Local State file, and writes the data in plain text to disk. Finally, the compiled RavenStealer.zip file is sent to the attacker's Telegram channel via the endpoint https://api.telegram.org/bot/sendDocument.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
