Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
New “Shuyal” Stealer Malware Emerges with Advanced Capabilities

New “Shuyal” Stealer Malware Emerges with Advanced Capabilities

by Tekmono Editorial Team
29/07/2025
in News
Share on FacebookShare on Twitter

A new infostealing malware, dubbed “Shuyal” by researchers at Hybrid Analysis, has emerged, demonstrating sophisticated capabilities in exfiltrating sensitive data from a wide array of browsers, including those focused on privacy.

Named Shuyal based on unique identifiers found in its executable’s PDB path, this previously undocumented stealer targets 19 different browsers. These include mainstream applications such as Chrome and Edge, as well as privacy-focused options like Tor, Brave, Opera, OperaGx, Yandex, Vivaldi, Chromium, Waterfox, Epic, Comodo, Slimjet, Coccoc, Maxthon, 360browser, Ur, Avast, and Falko. Beyond stealing credentials typically saved in browsers, Shuyal performs extensive system reconnaissance.

It gathers detailed information about disk drives, input devices, and display configurations. The malware also captures system screenshots and clipboard content. All collected data, including stolen Discord tokens, is exfiltrated via a Telegram bot infrastructure. Shuyal integrates aggressive defense evasion techniques.

Related Reads

Google opens applications for Gemini App Trusted Tester program

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

Upon deployment, it immediately disables Windows Task Manager by modifying the “DisableTaskMgr” registry value. It also maintains operational stealth through self-deletion mechanisms, using a batch file to remove traces of its activity after completing its primary functions. Once Shuyal is deployed, it attempts to access login credentials from its targeted browsers.

The malware spawns multiple processes to retrieve model and serial numbers of available disk drives, information about installed keyboards and mice, and details regarding attached monitors. It also captures a screenshot of current activity and steals clipboard data. The stealer utilizes PowerShell to compress collected data into a folder within the “%TEMP%” directory before exfiltration via the Telegram bot.

The malware is designed for stealth, deleting newly created files from browser databases and all files from the runtime directory that were previously exfiltrated. Shuyal also establishes persistence by copying itself to the Startup folder. The emergence of Shuyal highlights the continuously shifting threat landscape, influenced by factors such as law enforcement operations.

For instance, an FBI operation in May disrupted the Lumma stealer operation, though its resurgence indicates the adaptive nature of cybercriminals. While Hybrid Analysis did not disclose the distribution methods for Shuyal, other stealers have been disseminated through various means, including social media posts, phishing campaigns, and captcha pages.

Infostealing malware often serves as a precursor to more severe cyberattacks, such as ransomware, business email compromise (BEC), and other enterprise threats. Given the significant danger posed by infostealing malware, Hybrid Analysis researcher Vlad Pasca recommends that defenders leverage the insights provided in their blog post on Shuyal to develop more effective detection and defense mechanisms.

The post includes a comprehensive list of indicators of compromise (IOCs), such as files created by the stealer, processes spawned, and the address of the Telegram bot used for data exfiltration.

ShareTweet

You Might Be Interested

Google opens applications for Gemini App Trusted Tester program
News

Google opens applications for Gemini App Trusted Tester program

17/06/2026
Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
News

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

17/06/2026
Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
News

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

17/06/2026
SpaceX acquires AI coding startup Cursor for  billion in strategic move
News

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

17/06/2026
Please login to join discussion

Recent Posts

  • Google opens applications for Gemini App Trusted Tester program
  • Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
  • Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
  • SpaceX acquires AI coding startup Cursor for $60 billion in strategic move
  • Qualcomm unveils Snapdragon Reality Elite as next-gen XR platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.