Alpha Cyber

Is Your Data Safe? The Rising Threat of FredyStealer Malware

Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.

Alpha Cyber Research3 min readupdated 1 Apr 2026
FredyStealer Cover Photo

Malware Analysis Report

FredyStealer: The Silent Thief in Your System

Published March 26, 2026 · Threat Intelligence Team · 

A critical-severity script sample was processed by the malware analysis suite. The resulting write-up below is structured for publication and includes visuals, IOC tables, ATT&CK coverage, and operational guidance.

Verdict:

SUSPICIOUS

Risk:

72/100

Families:

No confident family match

Risk Score

72/100

Risk Score derived from this analysis run.

ATT&CK Techniques

0

ATT&CK Techniques derived from this analysis run.

IOCs

5

IOCs derived from this analysis run.

Signature Matches

14

Signature Matches derived from this analysis run.

Analysis Snapshot

Sample Name7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2.ps1
File TypeSCRIPT
VerdictSUSPICIOUS
Risk Score72/100
Detected FamiliesNo family confidently matched
Top ATT&CK TacticNo ATT&CK mapping available
File Size1348
MD57c420fcf3aab7e32a8dbc38481b0661a
IOC category distribution for this analysis.
ATT&CK tactic coverage derived from mapped techniques.

Threat Overview

This SCRIPT sample was classified as SUSPICIOUS with a risk score of 72/100. The narrative below is formatted for direct publication and is intended to help readers quickly understand what was found, why it matters, and what action should follow.

Technical Analysis

Behavioral Signals

Network behavior includes network:dga_detected. Behavioral tags: dga_activity, file_manipulation.

  • Ransom Notes

Structured Evidence Highlights

These normalized findings summarize the strongest technical evidence discovered across the parser, IOC, and ATT&CK stages.

Total indicators: 8 · High-confidence findings: 1

IndicatorCategorySeverityConfidence
Remote URL references embedded in script contentNetworkHighMedium
7cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2IocMediumMedium
7c420fcf3aab7e32a8dbc38481b0661aIocMediumMedium
55f916e466ff532214d8c71012cdf889c322513eIocMediumMedium
kms8.msguides.comIocMediumMedium
https://activat.my/ActSet.zipNetworkMediumMedium
https://activat.my/ActSet.zipIocMediumMedium
Script contains execution or staging primitivesStaticMediumMedium

Indicators of Compromise

The following tables are ready to paste into a WordPress or Elementor article. They include both the evidence itself and the recommended operational use for defenders.

TypeValueOperational Use
Domainkms8.msguides.comAdd to DNS sinkhole and monitor resolver logs.
URLhttps://activat.my/ActSet.zipBlock at secure web gateway and review access history.
SHA2567cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2Push to EDR blocklist and retrospective file search.
MD57c420fcf3aab7e32a8dbc38481b0661aUse for legacy detections and historical pivoting.
SHA155f916e466ff532214d8c71012cdf889c322513eUse for historical pivoting where SHA256 is unavailable.

File Hashes

HashValue
MD57c420fcf3aab7e32a8dbc38481b0661a
SHA155f916e466ff532214d8c71012cdf889c322513e
SHA2567cd8a6190b57fa29a3bca92b3e300766cf87bf07fd5036c40e39a0a2540d0fa2
SHA5125234769cd292ace0caa620d63c61f03d85a92484318c989cb127cbb90a874e91425cebba515bb090a69aa60bf7da584869ebd09ac0be2695ec899bf9797690d1

Signature Matches

The following detection content matched during analysis and can be cited as supporting evidence.

  • Username/Computer Name Check – Checks username or computer name for sandbox indicators
  • AV Exclusion Path Addition – Adds file paths to antivirus exclusions
  • Tor/Onion Communication – Communicates through Tor network or onion addresses
  • Email Collection – Collects emails from local clients or servers
  • BITS Job Abuse – Abuses BITS service for privilege escalation or persistence
  • Hidden File System – Creates hidden filesystem or storage area
  • Alternate Data Stream Hiding – Hides data in NTFS alternate data streams for covert storage
  • Registry-Based Payload Storage – Stores payload in registry keys for fileless execution

These actions are intentionally phrased so they can remain in the final published post as practical guidance.

  1. Share the IOC table and ATT&CK summary with defenders responsible for endpoint, network, and email controls.
  2. Search for the published indicators anywhere similar files may have been delivered or executed.
  3. Use the recommendations and visuals in this article to educate non-specialists on why the sample matters.

Impact Assessment

CRITICAL

Overall risk score of 72/100 places this sample in the critical severity tier.

  • System compromise with potential for data theft or unauthorized access

Overall severity: Critical (72/100)

Detection & Mitigation

Detection

  • Deploy file hash IOCs to EDR blocklists for immediate prevention
  • Create behavioral detection rules from API call sequences identified
  • Create SIEM correlation rules for network IOCs against firewall and DNS logs
  • Conduct retrospective hunting across historical logs for IOC matches

Mitigation

  • Isolate any systems where the sample or related IOCs have been identified
  • Update antivirus and EDR signatures with extracted hashes and behavioral indicators
  • Ingest all IOCs into threat intelligence platforms and SOAR playbooks
  • Share IOCs and findings with industry ISACs and threat intelligence sharing communities

Future Monitoring

  • Track recurrences of the IOC set across endpoint, proxy, DNS, and email telemetry.
  • Re-run analysis if new variants, delivery files, or related infrastructure are discovered.
  • Keep ATT&CK-aligned detection content synchronized with the mapped techniques in this article.

Conclusion

This critical-severity analysis generated 5 IOCs, and 14 signature references. The resulting article is designed to work as both a reader-friendly narrative and an operational handoff for defenders.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]