Cthulhu Stealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 21, 2025
Last Seen
November 21, 2025

Cthulhu Stealer is a malware family tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 21, 2025; most recent activity November 21, 2025.

Overview

Cthulhu Stealer is a data-stealing malware family that exfiltrates credentials and sensitive information from infected hosts. The article notes a new WhatsApp-based campaign deploying a hijacking worm, specifically targeting cryptocurrency users in Brazil, highlighting evolving propagation techniques and monetization vectors for this family. This underscores the threat of social-messaging–driven campaigns and account/session hijacking in crypto-focused threat activity.

Related Threat Clusters

  • WhatsApp Malware Campaign Targets Brazilian Crypto Users

    A sophisticated malware campaign in Brazil is exploiting WhatsApp to target cryptocurrency users, deploying a banking trojan named 'Eternidade Stealer.' This malware hijacks devices, steals financial data, and spreads…

    19 articles · Updated November 26, 2025
  • WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers

    A security flaw in WhatsApp allowed researchers to extract phone numbers of 3.5 billion users. The exploit involved systematically checking numbers through the app's discovery feature, revealing profile photos for 57%…

    56 articles · Updated November 18, 2025

Recent Intelligence Reports

  • Brazil Alerts Crypto Users to New WhatsApp Malware Campaign Deploying Hijacking Worm — Coinedition · November 21, 2025

CVSS v3.1 Breakdown