{"id":46174791,"url":"https://github.com/1rhino2/phantom-stealer","last_synced_at":"2026-03-02T17:41:34.772Z","repository":{"id":328792164,"uuid":"1112647135","full_name":"1rhino2/phantom-stealer","owner":"1rhino2","description":"A  Windows information stealer / credential stealer written in Go for security research and malware analysis. Demonstrates browser password extraction, crypto wallet theft, Discord token grabbing, and anti-analysis evasion techniques.","archived":false,"fork":false,"pushed_at":"2025-12-15T10:36:44.000Z","size":53,"stargazers_count":13,"open_issues_count":0,"forks_count":4,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-12-18T10:48:02.032Z","etag":null,"topics":["browser-stealer","credential-stealer","crypto-wallet-stealer","discord-token-grabber","golang","hacked","hacking","infostealer","loxy0dev","malware","password-stealer","pwn","pwned","redtiger","redtigertools","stealer","windows"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/1rhino2.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-12-08T23:05:50.000Z","updated_at":"2025-12-15T23:42:50.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/1rhino2/phantom-stealer","commit_stats":null,"previous_names":["1rhino2/phantom-stealer"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/1rhino2/phantom-stealer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/1rhino2%2Fphantom-stealer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/1rhino2%2Fphantom-stealer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/1rhino2%2Fphantom-stealer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/1rhino2%2Fphantom-stealer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/1rhino2","download_url":"https://codeload.github.com/1rhino2/phantom-stealer/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/1rhino2%2Fphantom-stealer/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30012057,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-02T17:00:27.440Z","status":"ssl_error","status_checked_at":"2026-03-02T17:00:03.402Z","response_time":60,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["browser-stealer","credential-stealer","crypto-wallet-stealer","discord-token-grabber","golang","hacked","hacking","infostealer","loxy0dev","malware","password-stealer","pwn","pwned","redtiger","redtigertools","stealer","windows"],"created_at":"2026-03-02T17:41:30.650Z","updated_at":"2026-03-02T17:41:34.754Z","avatar_url":"https://github.com/1rhino2.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Phantom Stealer\n\n\u003csub\u003e(Someone be my hero and make browser exfil work, I can't stand chrome.)\u003c/sub\u003e\n\n**EDUCATIONAL PURPOSES ONLY**\n\nA Windows information stealer / credential stealer written in Go for security research and malware analysis. Demonstrates browser password extraction, crypto wallet theft, Discord token grabbing, and anti-analysis evasion techniques.\n\nKeywords: stealer, infostealer, password stealer, credential stealer, browser stealer, cookie stealer, discord token grabber, discord stealer, telegram grabber, crypto wallet stealer, metamask stealer, phantom wallet, exodus stealer, chrome password stealer, edge password stealer, brave stealer, windows malware, golang malware, go stealer, rat, trojan, credential harvester, password dumper, DPAPI, token logger, session hijacker, redline stealer alternative, raccoon stealer, vidar stealer, mars stealer, aurora stealer, lumma stealer, stealc, rhadamanthys, mystic stealer, meta stealer, risepro, amadey, formbook, lokibot, azorult, predator stealer, kpot stealer, arkei stealer, oski stealer, research, malware analysis, reverse engineering, security research, red team, penetration testing, offensive security\n\n---\n\n## Table of Contents\n\n- [Disclaimer](#disclaimer)\n- [Features](#features)\n- [Targets](#targets)\n- [Technical Overview](#technical-overview)\n- [Building](#building)\n- [Project Structure](#project-structure)\n- [Detection \u0026 Defense](#detection--defense)\n- [Similar Projects](#similar-projects)\n- [Legal Notice](#legal-notice)\n- [License](#license)\n\n---\n\n## Disclaimer\n\n**THIS SOFTWARE IS PROVIDED FOR EDUCATIONAL AND RESEARCH PURPOSES ONLY.**\n\nThis project exists solely to:\n- Educate security researchers about credential theft techniques\n- Help security professionals understand attack vectors\n- Assist in developing better defensive measures\n- Demonstrate Windows API usage for legitimate security research\n\n**YOU ARE SOLELY RESPONSIBLE FOR YOUR ACTIONS.** The author(s) accept NO responsibility for misuse of this software. Using this tool against systems you do not own or have explicit written permission to test is **ILLEGAL** and **UNETHICAL**.\n\nBy downloading, copying, or using this software, you agree:\n1. To use it ONLY on systems you own or have written authorization to test\n2. To comply with all applicable local, state, federal, and international laws\n3. That the author bears NO liability for any damages or legal consequences\n4. This is for EDUCATIONAL purposes to understand threats and build defenses\n\n**If you're looking to actually steal data from people - don't. Get help.**\n\n---\n\n## Features\n\n### Browser Password Stealer\n- Chrome password stealer / Chrome password decryptor\n- Edge password stealer / Edge password recovery\n- Brave password stealer\n- Opera / Opera GX password grabber\n- Vivaldi password extraction\n- Firefox password decryption\n- Cookie stealer / session hijacker\n- Credit card data extraction\n- Autofill data grabber\n- Browsing history extraction\n- DPAPI decryption / CryptUnprotectData\n- AES-GCM decryption for modern Chrome\n\n### Crypto Wallet Stealer\n- Exodus wallet stealer\n- Electrum wallet grabber\n- Atomic wallet stealer\n- Coinomi wallet extraction\n- Bitcoin Core wallet.dat grabber\n- Ethereum keystore stealer\n- Monero wallet extraction\n- MetaMask extension stealer\n- Phantom wallet grabber (Solana)\n- Trust Wallet stealer\n- Coinbase Wallet grabber\n- Ronin wallet (Axie Infinity)\n- 40+ browser extension wallets supported\n\n### Token Grabber / Session Stealer\n- Discord token grabber / Discord token stealer\n- Discord token decryptor (encrypted tokens)\n- Telegram session stealer (tdata grabber)\n- Steam session stealer (SSFN grabber)\n- Steam config.vdf extraction\n\n### System Reconnaissance\n- Hardware/software inventory\n- Network configuration enumeration\n- Screenshot capture\n- Clipboard monitoring / clipboard stealer\n- WiFi password extraction (netsh)\n- Process enumeration\n- Installed software detection\n- Antivirus detection\n\n### Anti-Analysis / Evasion\n- Virtual machine detection (VMware, VirtualBox, Hyper-V)\n- Sandbox detection\n- Debugger detection (IsDebuggerPresent, NtQueryInformationProcess)\n- AMSI bypass / AMSI patching\n- ETW patching\n- Windows Defender exclusion\n- Anti-forensics techniques\n\n### Persistence Mechanisms\n- Registry Run key persistence\n- Startup folder persistence  \n- Scheduled task persistence\n- WMI event subscription persistence\n\n### Data Exfiltration\n- Discord webhook exfiltration\n- Telegram bot exfiltration\n- Zip archive creation\n- Automatic file organization\n\n---\n\n## Targets\n\n### Browsers Supported\nChrome, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Firefox, Waterfox, and more\n\n### Wallets Supported\nExodus, Electrum, Atomic, Jaxx, Coinomi, Guarda, Bitcoin Core, Litecoin Core, Dash Core, Monero, Zcash, Wasabi Wallet, Armory, Bytecoin, Binance\n\n### Browser Extension Wallets\nMetaMask, TronLink, Binance Chain, Coin98, Phantom, Trust Wallet, Coinbase Wallet, Ronin, Keplr, Solflare, Slope, Rabby, OKX Wallet, Petra, Martian, SubWallet, Nami, Eternl, and 30+ more\n\n### Platforms Targeted\nDiscord (desktop + browser), Telegram Desktop, Steam\n\n---\n\n## Technical Overview\n\nWritten in pure Go with minimal dependencies. Uses Windows API calls for:\n- DPAPI decryption (`CryptUnprotectData`)\n- Process enumeration\n- Registry operations\n- Screenshot capture (GDI)\n\n### Key Components:\n- **browsers/** - Chromium password/cookie decryption\n- **wallets/** - Crypto wallet file extraction\n- **tokens/** - Discord/Telegram/Steam token grabbing\n- **evasion/** - Anti-analysis techniques\n- **recon/** - System information gathering\n- **exfil/** - Data exfiltration (Discord/Telegram webhooks)\n\n---\n\n## Building\n\n```bash\n# Standard build\ngo build -o phantom.exe .\n\n# Production build (smaller, no debug symbols)\ngo build -ldflags \"-s -w -H windowsgui\" -o phantom.exe .\n\n# With garble for obfuscation (install: go install mvdan.cc/garble@latest)\ngarble -literals build -ldflags \"-s -w -H windowsgui\" -o phantom.exe .\n```\n\n**Requirements:**\n- Go 1.21+\n- Windows (uses Windows-specific APIs)\n- CGO enabled (for SQLite)\n\n---\n\n## Project Structure\n\n```\nphantom-stealer/\n├── main.go              # Entry point\n├── config/              # Configuration and targets\n├── browsers/            # Browser data extraction\n│   └── chromium.go      # Chromium-based browser handling\n├── wallets/             # Crypto wallet extraction\n├── tokens/              # Discord/Telegram/Steam tokens\n├── evasion/             # Anti-analysis techniques\n├── recon/               # System reconnaissance\n├── persist/             # Persistence mechanisms\n├── exfil/               # Data exfiltration\n└── syscalls/            # Windows API wrappers\n```\n\n---\n\n## Detection \u0026 Defense\n\n### How to Detect This Type of Malware:\n1. Monitor registry Run keys for suspicious entries\n2. Watch for SQLite database access in browser directories\n3. Detect DPAPI calls from non-browser processes\n4. Monitor webhook/API traffic to Discord/Telegram\n5. Use behavior-based AV that detects credential access patterns\n\n### How to Protect Yourself:\n1. Use a password manager (browser-stored passwords are vulnerable)\n2. Enable 2FA on all accounts\n3. Don't store sensitive files on Desktop/Documents\n4. Use hardware wallets for cryptocurrency\n5. Keep systems updated with EDR/AV solutions\n6. Be suspicious of random executables\n\n---\n\n## Legal Notice\n\nThis software is provided \"as-is\" without warranty of any kind. The author(s):\n\n- Do NOT condone illegal activity\n- Do NOT provide support for malicious use\n- Are NOT responsible for any damages caused\n- Created this ONLY for educational purposes\n\n**Unauthorized access to computer systems is a crime.** Penalties include:\n- **CFAA (US)**: Up to 10+ years imprisonment\n- **CMA (UK)**: Up to 10 years imprisonment  \n- Similar laws exist worldwide\n\nIf you use this tool illegally, you WILL eventually get caught. Modern forensics are very good.\n\n---\n\n## Similar Projects\n\nother open source stealers and security research projects you might find useful for comparison:\n\n- Redline Stealer (malware family - for analysis)\n- Raccoon Stealer (malware family - for analysis)  \n- Vidar Stealer (malware family - for analysis)\n- Mars Stealer (malware family - for analysis)\n- Aurora Stealer (malware family - for analysis)\n- Lumma Stealer (malware family - for analysis)\n- StealC (malware family - for analysis)\n- Rhadamanthys (malware family - for analysis)\n- various GitHub credential harvesting research projects\n\nthis project was built from scratch as a learning exercise, not forked from any existing stealer.\n\n---\n\n## License\n\nThis project is licensed under the MIT License - see below.\n\n```\nMIT License\n\nCopyright (c) 2025\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n```\n\n---\n\n## Notes\n\ntoo lazy to manually add commits, last minute github post lol\n\nthis started as a learning project to understand windows internals and how stealers actually work. figured id throw it up here in case anyone else finds it useful for defensive research or just wants to poke around the code.\n\nif you're a security researcher, hope this helps with your work. if you're trying to use this for actual malicious purposes, seriously reconsider your life choices.\n\nPRs welcome for educational improvements, bug fixes, or adding more detection methods to the defense section.\n\n### Related Topics\n\nmalware development, malware programming, windows malware, golang malware development, infostealer source code, stealer source code, password stealer source, credential stealer github, discord token grabber source, crypto stealer source, browser password recovery, DPAPI programming, windows api hacking, red team tools, offensive security tools, penetration testing tools, security research, malware analysis, reverse engineering malware, threat research, cybersecurity research, ethical hacking, bug bounty, ctf tools, windows security research\n\n---\n\n**remember: with great power comes great responsibility. use knowledge for good.**(Corny ahh, but we gotta keep it legally safe.)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F1rhino2%2Fphantom-stealer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2F1rhino2%2Fphantom-stealer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F1rhino2%2Fphantom-stealer/lists"}