ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://zarox.karatasyasin058.workers.dev/m/.

Database Entry


IOC ID:1885489
IOC: https://zarox.karatasyasin058.workers.dev/m/
IOC Type :url
Threat Type :botnet_cc
Malware: MicroStealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-08-24 07:46:22 UTC
Last seen:never
UUID:3fd5d539-9f1f-11f1-a7c1-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:CirrataGame CloudflareWorkers Discord Electron MicroStealer stealer

Avatar
Anonymous
Cloudflare Worker used as C2/exfil relay for 'Micro Stealer' (jar.microstealer), distributed as a trojanized Electron game 'CirrataGame'. Uploads AES-encrypted (.cryptedmicro) archives of stolen browser credentials, cookies, Discord tokens and ~90 crypto wallets; posts victim data to a Discord channel via a hardcoded bot token. Payload gang.jar SHA-256 59ecb9c1f70ec23f329350c5021591e69304759e648e5e6623a5927102c29637. Recovered via static deobfuscation 2026-08-23. TLP:CLEAR.