As reported by Bleeping Computer, a new information-stealing malware operation named Arkanix Stealer, which surfaced on dark web forums in October 2025, is suspected to be an experiment in AI-assisted malware development. The operation, characterized by a control panel and a dedicated Discord server for user interaction, was abruptly shut down by its author just two months after its launch, according to Kaspersky.Arkanix Stealer offered a range of typical data-stealing functionalities, including the ability to harvest system information, browser data from 22 browsers, cryptocurrency wallet details, and OAuth2 tokens. It could also steal Telegram and Discord credentials, spread through the Discord API, and target VPN credentials. A premium version, developed in C++ with VMProtect, included advanced features like RDP credential theft, anti-analysis techniques, and targeting of credentials for multiple gaming platforms. Researchers noted clues suggesting the use of large language models (LLMs) in its development, potentially accelerating the creation process.The rapid emergence and disappearance of Arkanix Stealer highlight the evolving landscape of malware development, where AI tools may significantly reduce creation time and costs, making such operations harder to track. The project's nature as a "public software product" rather than a clandestine operation suggests a possible test of LLM capabilities in malware engineering. The short lifespan, likely aimed at quick financial gain, underscores the challenges in attributing and mitigating rapidly evolving threats in the cybercriminal underground.Source: Bleeping Computer
Data Security, Malware, Threat Intelligence, AI/ML
Arkanix Stealer: AI-assisted malware operation emerges and disappears
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
