Join us at Black Hat and discover how we’re reshaping the cybersecurity landscape. Learn More

In early December, during an Advanced Continual Threat Hunt (ACTH) campaign investigation, LevelBlue SpiderLabs discovered a new malware named Ov3r_Stealer.

At a high level, this malware is designed to steal credentials and crypto wallets and send those to a Telegram channel that the threat actor monitors. The tactics and techniques to drop the malware and the code itself is not unique, but because this malware was relatively unknown at the time of discovery, it allowed our investigators to dig a little deeper into its backstory and potentially the origins of this malware.

Related Resources

Current: resourcesresearch-reportsfacebook-advertising-spreads-novel-malware-variant
Resource: resourcesresearch-reportsttp-briefing-q2-2026
Research Report

Q2 TTP Briefing: Latest Threats & Trends from the Frontlines

Current: resourcesresearch-reportsfacebook-advertising-spreads-novel-malware-variant
Resource: resourcesresearch-reportsquimarat-a-java-rat-with-burning-ambitions
Research Report

QuimaRAT: A Java RAT with Burning Ambitions

Current: resourcesresearch-reportsfacebook-advertising-spreads-novel-malware-variant
Resource: resourcesresearch-reportsttp-briefing-q1-2026
Research Report

Q1 2026 TTP Briefing: Latest Threats & Trends from the Frontlines