AI-assisted Arkanix Stealer: a fleeting dark-web info-stealer experiment

Kaspersky researchers say Arkanix Stealer, promoted on dark-web forums in Oct 2025, was likely an AI-assisted, short-lived information-stealer project with Python and native C++ versions, a Discord community, and a referral scheme. It could harvest browser data (including 0Auth2 tokens), cryptocurrency wallet data, and credentials from Telegram and Discord, plus local-file exfiltration and modular plugins. The premium variant added anti-sandbox/debugging, RDP credential theft, and advanced post-exploitation tools like ChromElevator to bypass protections. The operation’s unclear purpose points to rapid, low-cost AI-driven malware development rather than a sustained campaign, with IoCs published by Kaspersky.
- Arkanix Stealer pops up as short-lived AI info-stealer experiment BleepingComputer
- AI-augmented threat actor accesses FortiGate devices at scale | Amazon Web Services Amazon Web Services (AWS)
- Hackers Used AI to Breach 600 Firewalls in Weeks, Amazon Says Bloomberg
- AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries The Hacker News
- AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign theregister.com
Reading Insights
1
7
3 min
vs 4 min read
88%
788 → 93 words
Want the full story? Read the original article
Read on BleepingComputer