Skip to content
ThreatCluster

KuinaExtractor Infostealer Targets Browser Data and Crypto Wallets

First seen 26 Jun 2026, 13:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 11:26 UTC
  • •KuinaExtractor is a Rust-based infostealer targeting browser data and crypto wallets.
  • •The malware uses Telegram for exfiltration and employs UAC bypass techniques.
  • •It has been evolving for over six months, indicating a sustained threat to users.

The newly identified KuinaExtractor infostealer, written in Rust, has been evolving for over six months and poses a significant threat to users across various platforms. It targets sensitive data, including browser information, cryptocurrency wallets, and credentials for popular services like Roblox, Steam, and Discord. The malware employs advanced techniques such as Telegram for data exfiltration, User Account Control (UAC) bypass, and sandbox detection to enhance its stealth capabilities. Analysis indicates a single-operator lineage with a focus on concealment rather than new features. The ongoing threat is compounded by its ability to affect a wide range of users, making it a growing concern in the cybersecurity landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-26
KuinaExtractor identified
Researchers uncovered the KuinaExtractor infostealer, which has been evolving for over six months, targeting sensitive user data.
Gbhackers
2026-06-26
Malware analysis reveals stealth techniques
The infostealer employs Telegram for data exfiltration, UAC bypass, and sandbox detection to avoid detection.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track K0to in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed