Stealerium Malware Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 3, 2025; most recent activity December 3, 2025.
Stealerium is a credential-stealing malware family that targets browsers and other installed apps to exfiltrate passwords, cookies, and other sensitive data. The latest campaign disguises the malware as an 'Executive Award' and employs ClickFix as part of its delivery/infection chain, illustrating evolving social-engineering tactics to broaden reach and evade defenses.
A new campaign named 'Executive Award' is exploiting ClickFix to distribute Stealerium malware. This malware targets users by masquerading as a legitimate award notification, potentially compromising sensitive…