Meduza Stealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
October 31, 2025
Last Seen
May 6, 2026

Meduza Stealer is a malware family tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity May 6, 2026.

Overview

Meduza Stealer is a credential-stealing malware family used to exfiltrate data from infected hosts. Recent reports place its developers under arrest in Russia, with the case described as linked to a government hack, highlighting a high-profile law enforcement action against a cybercrime operation.

Related Threat Clusters

Recent Intelligence Reports

  • Yet Another Way to Bypass Google Chrome's Encryption Protection — Darkreading · May 6, 2026
  • How VoidStealer bypasses Chrome's protections to hijack sessions and steal data — Kaspersky · May 6, 2026
  • Unc3944 Sms Phishing Sim Swapping Ransomware — www.mandiant.com · April 28, 2026
  • Russia Arrests Meduza Stealer Developers After Government Hack — Feeds.Feedburner · October 31, 2025
  • Meduza Stealer Developers Arrested in Russia — Rss.App · October 31, 2025

CVSS v3.1 Breakdown