Skip to content
NWHStealer Spreads via Fake Proton VPN and Game Mods

NWHStealer Spreads via Fake Proton VPN and Game Mods

Socprime April 16, 2026

A Windows infostealer known as NWHStealer is spreading through fake VPN download pages, bundled hardware utilities, mining tools, and compromised gaming mods. The malware is typically delivered in malicious ZIP archives that rely on self-injection, DLL hijacking, and process hollowing, with RegAsm frequently used as the target process. Once executed, NWHStealer steals browser credentials, collects cryptocurrency wallet data, and exfiltrates the stolen information through encrypted command-and-control channels.

Researchers identified two primary delivery methods. In one, malicious ZIP archives hosted on a free web-hosting platform launched the stealer through self-injection. In the other, fake Proton VPN websites delivered a DLL-based loader that abused DLL hijacking. The loader then decrypted embedded resources, hollowed out a RegAsm process, and finally executed NWHStealer in memory or injected it directly into browser-related processes.

Users should avoid downloading software from untrusted sources, including unofficial GitHub releases, suspicious SourceForge pages, and links shared through YouTube descriptions. Organizations should verify digital signatures before execution, use endpoint security tools that block known malicious URLs, and watch for suspicious scheduled tasks or hidden directories created within user profile paths.

Defenders should hunt for known NWHStealer DLL names, RegAsm process injection activity, hidden folders under LOCALAPPDATA , and scheduled tasks that launch binaries disguised as legitimate system files. The identified command-and-control domains and Telegram dead-drop link should be blocked immediately. Any affected systems should be isolated and investigated through full forensic analysis.

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.