Introduction
Toward the end of 2025, cybersecurity researchers identified a malicious campaign that lasted several months, built around a piece of software called Arkanix Stealer. This is a program designed to silently steal personal data from victims’ devices, without them noticing. The campaign has since concluded, but the case offers a useful lesson on how certain attacks work and how to protect yourself.
What happened
Arkanix Stealer is malware — that is, a malicious program — available in two different technical versions (one written in C++, the other in Python). Those who created it distributed it through common channels such as phishing emails, Discord groups, and online forums, disguising it as seemingly useful tools — for example, in the form of a fake program to verify Steam accounts.
Once installed on the victim’s computer, the program attempted to collect as much information as possible: login credentials saved in browsers, session cookies, browsing history, authentication tokens for online services, cryptocurrency wallet data such as Exodus and Electrum, account information from gaming platforms like Steam, Epic, and Riot, Discord tokens, Telegram data, Wi-Fi network information, saved remote connections, and technical details about the device such as operating system, processor, and memory.
The program used techniques to bypass computer defense systems and to avoid being analyzed in secure environments used by researchers. It was also capable of spreading autonomously through Discord by sending messages to other users. Behind this operation was an affiliate program, now discontinued. The identity of the authors remains unknown.
Why it matters
Even though no specific victims have been disclosed, the scope of what Arkanix could steal is significant. Losing login credentials, authentication tokens, or cryptocurrency data can have real consequences: unauthorized access to accounts, loss of digital assets, and identity theft. The fact that the malware also spread through Discord — a platform widely used by young people and gamers — broadens the potential pool of people at risk.
What organizations and users can do
Do not download programs from unofficial sources, especially if they promise features that seem too convenient or free. Be wary of links received on Discord or forums even from known contacts, as the malware spread autonomously. Use a dedicated password manager instead of saving credentials in the browser. Enable two-factor authentication on all services that support it. Keep your operating system and antivirus software up to date.
Final takeaways
- Arkanix Stealer was malware distributed disguised as legitimate tools on Discord and forums, active for several months toward the end of 2025.
- It aimed to steal a very wide range of personal data, from passwords to cryptocurrencies to gaming accounts.
- The authors are still unknown and the affiliate distribution channel has been shut down, but the case serves as a reminder of how important it is to download software only from trusted sources.
Sources
https://securelist.com/arkanix-stealer/119006/
https://www.dexpose.io/deep-dive-into-arkanix-stealer-and-its-infrastructure/
https://www.gdatasoftware.com/blog/2025/12/38306-arkanix-stealer
Source: BleepingComputer