Screenshot of the Xillen Stealer portal | Image: Darktrace
Darktrace analysts are sounding the alarm over a rapidly evolving cross-platform information-stealing malware family known as Xillen Stealer, whose newly released v4 and v5 versions significantly expand targeting capabilities, introduce advanced evasion mechanisms, and adopt multiple modern C2 and exfiltration techniques.
Xillen Stealer is marketed openly on Telegram, with licenses offered through a professional dashboard for buyers. The criminal panel operators browse logs, infected hosts, and subscription tiers.
Darktrace notes that Xillen v4/v5 steals from an unusually broad ecosystem:
- 100+ browsers (Chrome, Chromium, Brave, Ghost, Floorp, Waterfox, Tor, Arc, Sidekick, Pale Moon, K-Meleon, etc.)
- 70+ cryptocurrency wallets, including Ledger, MetaMask, Exodus, AtomicDEX, Rabby, Phantom, Trezor, Wasabi, and MyEtherWallet
- Password managers, including LastPass, BitWarden, Dashlane, KeePass, NordPass
- Developer environments (VS Code, JetBrains, Sublime, Eclipse)
- Cloud credentials for AWS, GCP, Azure, DigitalOcean, Heroku
- Containers & DevOps systems: Docker, Kubernetes configs/secrets
- SSO tokens (Azure AD, Kerberos, Google Cloud)
- TOTP 2FA tokens
- VPN configurations (WireGuard, NordVPN, ExpressVPN, Cisco AnyConnect, Pulse Secure)
As Darktrace summarizes,Β βThe main functionality of Xillen Stealer is to steal cryptocurrency, credentials, system information, and account information from a range of stores.β
One of the most attention-grabbing updates is the so-called AI Target Detection module. Darktrace writes, βWhile the class is named βAITargetDetectionββ¦ there is no actual implementation of machine learning. Instead, the system relies entirely on rule-based pattern matching.β
Nevertheless, the intent is clear. The rules prioritize:
- High-value countries (US, UK, Germany, Japan)
- Crypto-friendly jurisdictions
- Wealth-related keywords like CEO, trader, investor, VIP
Darktrace warns that βEven though AI is not actually implementedβ¦ it shows how malware developers could use AI in future malicious campaigns.β
Modern security products increasingly rely on AI/ML, so Xillen Stealer introduces a module specifically to fool them.
According to the report, ββAIEvasionEngineβ is designed to help malware evade AI-based or behavior-based detection systemsβ¦ mimicking legitimate user behavior, injecting statistical noise, randomizing timing, and camouflaging resource usage.β
The source code shows the entropy-variance code that simulates random workloads.
Techniques include:
- Fake mouse movements and browsing
- Random file & network activity
- Irregular sleep patterns
- CPU/RAM usage shaped to look like Notepad or Chrome
- API & memory access obfuscation
Xillen Stealer v4/v5 packages a Rust-based polymorphic engine. βThe βPolymorphicEngineββ¦ recognized instruction patterns with randomized alternatives, then applies control flow obfuscation and inserts non-functional code to increase variability. Additional features include string encryption via XOR and a stub-based packer.β
This makes each build unique, complicating static signatures and antivirus detection.
The malware includes a function that extracts Kubernetes cluster secrets. Darktrace explains: βThe βDevToolsCollectorβ is designed to collect sensitive data related to a wide range of developer tools and environmentsβ¦ IDE configs, cloud credentials, Docker/Kubernetes configs, Git credentials, database connections, API keys, FTP configs.β
This positions Xillen Stealer as a threat not just to personal users, but also:
- DevOps
- SRE teams
- Software companies
- Cloud administrators
Xillen implements multiple steganographic methods:
- LSB image encoding
- NTFS Alternate Data Streams
- Registry-based hiding
- Slack space
- Image + archive polyglots
- EXIF metadata embedding
- Whitespace encoding
Darktrace notes,Β βThe βSteganographyModuleβ hides the stolen data by embedding it within images or unallocated disk space to stage it for exfiltration.β
Darktrace highlights the CloudProxy module: βThe CloudProxy class is designed for exfiltrating data by routing it through cloud service domainsβ¦ allowing the traffic to blend in.β
The malware attaches timestamps and SHA-256 signatures, then POSTs data through cloud-themed URLsβintended to be replaced by attacker cloud accounts.
Xillenβs C2 system is highly resilient. Darktrace explains, βThe βP2PEngineβ provides multiple methods of C2, including embedding instructions within blockchain transactionsβ¦ exfiltrating data via Tor and I2Pβ¦ and storing payloads on IPFS. It also supports domain generation algorithms to create dynamic .onion addresses.β
Xillen Stealer appears to be developed by a self-described 15-year-old βpentest specialist.β The group distributing it, βXillen Killersβ, claims to have 3,000 members.β
The same group claims involvement in:
- Analyzing Project DDoSia
- Compromising doxbin.net
- Finding vulnerabilities on Russian and Ukrainian websites
With extensive credential theft, steganography, polymorphism, DevOps targeting, and blockchain-backed C2, Xillen Stealer v4/v5 represents one of the most ambitious and wide-scope information-stealing platforms seen in 2025.
Related Posts:
- Darktrace Exposes “Fake Startup” Malware Campaign: Lures Crypto Users with AI/Web3 Apps to Steal Wallets
- DragonForce Ransomware Strikes Manufacturing Sector with Brute-Force, Exfiltrating Data Over SSH to Russian Host
- Venom Spider Evolves: Arctic Wolf Exposes More_eggs Campaign Targeting HR
- SocGholish Reloaded: Darktrace Uncovers Ransomware-Primed Loader Campaign
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.