• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-45829

    Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution

    non-consensual intimate image

    UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content

    private ISAC

    US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

    travel booking fraud

    Dubai Police Issues Urgent Warning on Fake Travel Offers Flooding Social Media

    AntV, Shai-Hulud, NPM, Supply Chain, Supply Chain Attacks, Malware, Worm, Golden Path

    Massive npm Supply Chain Attack Hits AntV Ecosystem; Hundreds of JavaScript Packages Compromised

    Eurovision cyberattack

    Austria Blocks Eurovision Cyberattack During Contest Week

    CVE-2026-42945

    Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack

    AI-driven cyber risks

    Global Banks Scramble After AI Tool Exposes Cyber Weaknesses

    7-Eleven data breach

    7-Eleven Confirms Hack After Appearing on ShinyHunters Leak List

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Claude AI, Antropic, AI, Artificial Intelligence

    U.S. Will Now Examine National Security Implications of New AI Models, Pre-Release

    U.S. Government Sues TikTok, TikTok

    UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-45829

    Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution

    non-consensual intimate image

    UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content

    private ISAC

    US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

    travel booking fraud

    Dubai Police Issues Urgent Warning on Fake Travel Offers Flooding Social Media

    AntV, Shai-Hulud, NPM, Supply Chain, Supply Chain Attacks, Malware, Worm, Golden Path

    Massive npm Supply Chain Attack Hits AntV Ecosystem; Hundreds of JavaScript Packages Compromised

    Eurovision cyberattack

    Austria Blocks Eurovision Cyberattack During Contest Week

    CVE-2026-42945

    Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack

    AI-driven cyber risks

    Global Banks Scramble After AI Tool Exposes Cyber Weaknesses

    7-Eleven data breach

    7-Eleven Confirms Hack After Appearing on ShinyHunters Leak List

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Claude AI, Antropic, AI, Artificial Intelligence

    U.S. Will Now Examine National Security Implications of New AI Models, Pre-Release

    U.S. Government Sues TikTok, TikTok

    UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Creal Information Stealer Phish Out Cryptocurrency Users

Creal information stealer was circulated to users using a spoofed website and a YouTube channel with over 50 million subscribers

Editorial by Editorial
May 2, 2023
in Firewall Daily, Malware News
0
Creal
670
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

A new type of malware called “Creal Stealer” was found targeting cryptocurrency users through phishing sites. The Creal information stealer steals sensitive information such as login credentials and private keys to access cryptocurrency wallets.

According to the researchers at the Cyble Research and Intelligence Labs (CRIL), the Creal information stealer is distributed through phishing websites that appear to be legitimate cryptocurrency exchange or wallet websites.

Once the victim enters their login credentials or private keys on the phishing site, the Creal information stealer automatically steals the information and sends it to the attacker’s server.

Creal Stealer’s builder and source code are available on GitHub, which enables TAs to modify the code to suit their requirements,” said the CRIL report.

This can result in the emergence of various stealers from Creal Stealer’s source code, posing a significant threat to users,” it added.

Creal Information Stealer: Mode of operation

CRIL researchers found Creal information stealer’s builder and source code on GitHub, which can be further misused and worked on to increase its capabilities. CRIL also found a phishing website that impersonated a cryptocurrency mining platform.

report-ad-banner

This spoofed website was used to infect users with the Creal information stealer.

The Phishing website hosting Creal information stealer (Photo: Cyble)

Technical details related to ‘Kryptex’ phishing website

Creal information stealer was spread to unsuspecting users on the fraudulent Kryptex website. Creal payload on Dropbox was found on the following URL –

  1. hxxps[:]//www[.]dropbox[.]com/s/dl/x4vgcaac6hcdgla/kryptex-setup-4.25.7[.]zip.

Its binary was compiled using PyInstaller in Python –

  1. f3197e998822bc45cb9f42c8b153c59573aad409da01ac139b7edd8877600511

After extracting the contents of the file made using PyInstaller, the Creal payload was found as a PYC file.

Creal information stealer file (Photo: Cyble)

Creal, the open-source stealer was used for crypto frauds on YouTube. A YouTube channel that had over 10 million subscribers was wiped clean of its original content. Access to the YouTube channel by cybercriminals was gained by exploiting session cookies, according to reports.

Cybercriminals added two fraudulent videos to the YouTube channel detailing cryptocurrency.

Technical details of Creal stealer

  1. URL – kryptex[.]software

1.1 hxxps[:]//www.dropbox[.]com/s/dl/x4vgcaac6hcdgla/kryptex-setup-4.25.7[.]zip

  1. Zip archive – 929e6f2c8896059c72368915abcaefa2
    7122f0b88607061806fd62282e8b175ae28b7e29
    f3197e998822bc45cb9f42c8b153c59573aad409da01ac139b7edd8877600511
  2. Creal information stealer SHA1 SHA256 – bb2ca78ffff72d58599d66bf9b2f0ae6
    20dcb84660e5f79a98c190d3d455fce368d96f35
    4ee417cbefa1673d088a32df48b8182bdad244541e8dc02faf540b9aa483fdcb

Creal information stealer: Snoop before strike

Creal information stealer checks the presence of the stolen username in the ‘blacklistedUsers’ list in the stealer binary. If the credentials are indeed in the list, the execution of Creal gets stopped. Or it continues to check if it is running in a protected environment.

Creal checks for the hostname of the targeted device using the socket.gethostname() method. It checks for the hostname to be on the blacklisted list. The same action of terminating itself is conducted if the search result is positive. To terminate itself, Creal information stealer executes the os._exit(0) function.

The information-stealing malware would check the MAC address of the machine to be present in the blacklisted MAC addresses.

Creal info stealer would check the public IP address in the blacklist called ‘sblacklist’ by first running a curl command to obtain the IP address. Creal would not run if the IP was found in the blacklist.

Creal would also check for specific Python modules in the absence of which it would install the modules using pip.

Following the environment check, the Creal information stealer would maintain persistence by copying itself to AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ directory using the shutil.copyfileobj() function.

Thereafter, Creal would assign values to variables including paswWords, GamingZip, CookiCount, and WalletsZip among others to target them. It would steal login credentials and cookies from the browser. It exfiltrates data using Discord webhook.

Figure 9 Targeted Applications

Targeted applications (Photo: Cyble)

Creal information stealer GitHub repository

Over 50 Creal information stealer samples were found in the wild indicating its possible usage in the hands of threat actors.

Creal information stealer: Caution steps

Campaigns targeting cryptocurrency users have been in the cybersecurity news for some time.

Threat Actors are taking advantage of this recent collapse of the Silicon Valley Bank, conducting various malicious activities including cryptocurrency scams target unsuspecting victims, The Cyber Express reported recently.

Cybercriminals are increasingly adopting the practice of using open-source code in their malware, as it enables them to craft complex and tailored attacks while keeping costs at a minimum, noted the CRIL report.

The CRIL report advise cryptocurrency users to be cautious when accessing exchange or wallet websites and to verify the website’s authenticity before entering any sensitive information.

It has also recommended that users use two-factor authentication and other security measures to protect their cryptocurrency assets from theft.

Cyble has informed relevant authorities about the Creal information stealer and is working to mitigate its spread. The report has also provided a list of indicators of compromise (IOCs) to help other organizations identify and mitigate the malware.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: Creal information stealerCreal phishing siteCreal YouTube channelThe Cyber ExpressThe Cyber Express News
Previous Post

Mozilla Foundation Releases New Advisory on Thunderbird Vulnerability

Next Post

Fake Accounts Are a Bigger Problem Than Businesses Realize

Next Post
Fake Accounts

Fake Accounts Are a Bigger Problem Than Businesses Realize

Upcoming Webinar

Sectoral Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

CVE-2026-45829
Firewall Daily

Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution

May 20, 2026
Chanhassen Dinner Theatres cyberattack
Cyber News

Chanhassen Dinner Theatres Cyberattack Forces More ‘Guys and Dolls’ Cancellations

May 20, 2026
non-consensual intimate image
Firewall Daily

UK Regulator Ofcom Cracks Down on Viral Deepfake Nude Content

May 20, 2026
private ISAC
Firewall Daily

US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

May 20, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information