{"id":5105,"date":"2025-07-04T10:03:42","date_gmt":"2025-07-04T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/04\/new-123-stealer-advertised-on-underground-hacking-forums-for-120-per-month\/"},"modified":"2025-07-04T10:03:42","modified_gmt":"2025-07-04T10:03:42","slug":"new-123-stealer-advertised-on-underground-hacking-forums-for-120-per-month","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/04\/new-123-stealer-advertised-on-underground-hacking-forums-for-120-per-month\/","title":{"rendered":"New \u201c123 | Stealer\u201d Advertised on Underground Hacking Forums for $120 Per Month"},"content":{"rendered":"<p>    New \u201c123 | Stealer\u201d Advertised on Underground Hacking Forums for $120 Per Month<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new credential-stealing malware dubbed \u201c123 | Stealer\u201d has surfaced on underground cybercrime forums, being marketed by threat actor \u201ckoneko\u201d for $120 per month.\u00a0<\/p>\n<p>This malware-as-a-service (MaaS) offering represents the latest evolution in information stealer technology, combining sophisticated data exfiltration capabilities with a user-friendly administrative interface.<\/p>\n<pre class=\"wp-block-preformatted\"><strong>Key Takeaways<\/strong><br>1. \"123 | Stealer\" marketed for $120\/month by threat actor \"koneko\" on underground forums.<br>2. C++ coded, DLL-free (~700KB), supports 70+ browser extensions, requires self-hosted proxy servers.<br>3. Steals browser data, passwords, crypto wallets, Discord accounts, and performs file\/process grabbing.<br>4. Professional presentation but lacks cybercriminal reviews, making effectiveness uncertain<\/pre>\n<p>The stealer targets a comprehensive range of sensitive data, demonstrating the increasing commercialization of cybercrime tools.\u00a0<\/p>\n<p>According to the forum advertisement, the malware harvests browser data, cookies, stored passwords, cryptocurrency wallet information, and browser extensions.\u00a0<\/p>\n<p>The threat actor claims the stealer can also perform process grabbing and file grabbing operations, making it a versatile tool for data theft operations.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfm4iKjDixJ0ux-awiMoP5CiY-djg6IGztViHxPTAswUNi_CZ3T4-X6yasHL9KxkKuGkSUt_1TrV0UDWdSINp2Wxil-h3Qs3cfYBR2DcKA8IvBD1y1UCpEBTbS1n9qfVem6Uupa_Q?key=PEPpPcIwqddajQz_AhD2qA\" alt=\"\"><figcaption class=\"wp-element-caption\">Threat actor Koneko Offers $120\/Month Credential Stealer<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>123 | Stealer Bypasses AV, Targets Browsers and Crypto Wallets<\/strong><\/h2>\n<p>According to the Kraken Labs report, 123 | Stealer is written in C++, a programming language choice that suggests developers prioritized performance and low-level system access.\u00a0<\/p>\n<p>The malware features a DLL-free stub architecture, weighing approximately 700KB, which makes it more difficult to detect by traditional antivirus solutions that rely on dynamic link library (DLL) injection detection methods.<\/p>\n<p>One notable aspect is the proxy server requirement. Users must establish their own proxy infrastructure using Ubuntu or Debian-based servers, indicating a sophisticated command and control (C2) architecture.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdhfEHuZbBaLtJVJAzUX5UsaR9tmiSf1R2KFIjehjTt9GtITjlMV3OaTO2D1z9BJILvKfhe3qnmGxCPhvdQ1mF0Nj1bNKuLY0WR2KoYcuTRaE59FKY5m1Ufz2lyksiEP63sPEEGaQ?key=PEPpPcIwqddajQz_AhD2qA\" alt=\"\"><figcaption class=\"wp-element-caption\">Targeting browsers<\/figcaption><\/figure>\n<\/div>\n<p>This approach allows malware operators to maintain operational security (OPSEC) while distributing infrastructure burden to customers.<\/p>\n<p>The administrative panel reveals extensive browser support, including compatibility with over 70 browser extensions.\u00a0<\/p>\n<p>The stealer targets major Chromium-based browsers such as <a href=\"https:\/\/cybersecuritynews.com\/chrome-turn-webpages-into-podcasts\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Chrome<\/a>, Opera, and Chromium itself, as well as Gecko-based browsers like Firefox variants.\u00a0<\/p>\n<p>Popular applications, including Discord, Battle.net, and various cryptocurrency wallets, are also within the malware\u2019s scope.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Mid-Tier Threat, Costs $120 Monthly<\/strong><\/h2>\n<p>The $120 monthly subscription model positions 123 | Stealer in the mid-tier market segment of information stealers.\u00a0<\/p>\n<p>This pricing strategy targets both novice cybercriminals and experienced threat actors seeking reliable data exfiltration tools. The subscription model ensures recurring revenue for malware authors while providing continuous updates and support to customers.<\/p>\n<p>The forum advertisement emphasizes that users are responsible for any detection or force majeure events, indicating that malware authors are attempting to limit their liability.\u00a0<\/p>\n<p>Additionally, the service explicitly prohibits operations in Russia, CIS countries, and former Soviet republics, a common restriction among cybercrime services.<\/p>\n<p>Currently, the malware has not received public reviews from other cybercriminals on the forum, making its actual effectiveness unverified.\u00a0<\/p>\n<p>However, the professional presentation of the login interface and comprehensive administrative panel suggests significant development <a href=\"https:\/\/cybersecuritynews.com\/europol-dismantles-fraud-crypto-investment-ring\/\" target=\"_blank\" rel=\"noreferrer noopener\">investment<\/a>, indicating this may be a serious threat rather than a scam operation.<\/p>\n<p>Security researchers and organizations should monitor for 123 | Stealer samples and update detection signatures to protect against this emerging threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt; <a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a>\u00a0<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/123-stealer-on-underground-hacking-forums\/\">New \u201c123 | Stealer\u201d Advertised on Underground Hacking Forums for $120 Per Month<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/123-stealer-on-underground-hacking-forums\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New \u201c123 | Stealer\u201d Advertised on Underground Hacking Forums for $120 Per Month A new credential-stealing malware dubbed \u201c123 | Stealer\u201d has surfaced on underground cybercrime forums, being marketed by threat actor \u201ckoneko\u201d for $120 per month.\u00a0 This malware-as-a-service (MaaS) offering represents the latest evolution in information stealer technology, combining sophisticated data exfiltration capabilities with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1112,258],"tags":[130],"class_list":["post-5105","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-hacking-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5105"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5105"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5105\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}