Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Kleptomania Stealer Targets Browser Passwords, Session Cookies and Crypto Wallets

Kleptomania Stealer Targets Browser Passwords, Session Cookies and Crypto Wallets

Last updated:September 9, 2026
Human Written
  • A new Windows info stealer called Kleptomania Stealer is currently listed for sale on a cybercrime forum.

  • The seller says it can steal passwords, browser cookies, card data, crypto wallets and app sessions. The post also lists many browsers, wallets, chat apps, VPN tools, and FTP clients.

  • There is a key warning. No public malware study found in this review proves the full list of claims. The size, 98% report rate, and app support also come from the seller.

New Kleptomania Stealer Malware Offered for Sale on Cybercrime Forum

The listing says Kleptomania can take browser passwords, cookies, history, autofill data, and saved card data. It also claims to take CVV and CVV2 data, Google OAuth tokens, and screenshots.

The seller says it works with more than 70 Chromium browsers and more than 35 Gecko browsers. It also claims more than 125 crypto browser add-ons.

Named apps include Chrome, Edge, Brave and Firefox. The list also names MetaMask, Phantom, Trust Wallet, Exodus, and Electrum.

Telegram and Discord are also on the list. The seller claims more than 20 game apps, 15 chat apps, 15 VPN tools, and 20 FTP tools.

These claims match a known malware trend. MITRE says malware can pull saved usernames and passwords from web browsers. It also tracks threats that steal browser cookies and other login data.

Session Theft could be a Major Risk

One of the most practical features of the malware that might assist the criminals in their illegal activities would be the ability to steal sessions. Session cookies could allow a hacker to use a site as an already logged in user. MITRE notes that, in some cases, stolen cookies may bypass the MFA authentication.

That does not mean Kleptomania can beat MFA on every site. Each service uses its own rules to protect sessions. Other stealers show that this type of theft is real. MITRE says Lumma Stealer can collect browser cookies. It also lists other data theft actions linked to the malware.

Crypto Theft is a Key Target

Kleptomania also puts a strong focus on crypto. The seller claims support for more than 65 desktop wallets and more than 125 browser wallet add-ons.

It also lists a seed phrase scanner. A seed phrase can restore a crypto wallet. If malware finds one on a PC, a thief may use it to take the funds. This is not a new malware trick. Security teams have seen other stealers target crypto wallets along with browser data.

The seller also lists a clipper as a planned feature. Clippers can change a copied crypto address before a victim sends funds.

The Malware Uses a Subscription Model

According to reports, Kleptomania is being marketed as a malware-as-a-service. The seller quoted $150 for a one-month subscription, $400 for three months, and $1,500 for one year subscription. Besides, they claim the build size is approximately 700KB. The post also claims a 98% report rate.

No independent lab has tested either of the claims. A small file does not prove that malware is hard to spot. A high report rate also does not prove that it can steal data from most victims.

The listing also mentions anti-VM tools and code hiding. These are common features in malware that criminals often purchase. They can help a program avoid some checks and make study harder.

The seller says more modules are planned. They include a loader, clipper, HVNC tool and a macOS version. The post also lists smart file grab and sort tools. If added, these tools could expand what buyers can do. But planned features are not confirmed features.

What we Know so Far

The biggest gap is between the ad and hard evidence. The available report shows that someone is marketing a product under the Kleptomania name. There’s no evidence to prove if anyone has used it, how many have used it, who the operators are, or how the malware spreads.

There’s also no proof that it works on every browser, wallet or app on the list as the seller claimed. That matters because malware sellers often use long feature lists to draw buyers. Some items may be planned, limited or not work as well as the ad suggests.

The broad target list is notable, but it is still only a marketing claim. A sample and lab test would show which tools work and what data the malware can really collect. For now, Kleptomania is just an emerging Windows malware offer, not a known large attack wave.

Its listed features are possible. Browser password theft, cookie theft, screen capture, and crypto theft are all known malware tactics. MITRE tracks these methods across many threats.

Kleptomania reflects a wider infostealer surge. Flashpoint recorded 7.4 million infected hosts and 1.7 billion stolen credentials in H1 2026, a 27% increase. Vidar, StealC, and Lumma remained the leading infostealers, while AI is automating identity harvesting.

There’s a need for further study to confirm Kleptomania’s code, spread methods, control servers, and real theft rate. Until then, the clearest finding is simple: criminals are marketing a Windows stealer with a very broad list of claimed targets.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.