Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow.
Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.
What STRU Discovered:
- AI-assisted development: The developer openly credits Gemini for helping build the malware, including its App-Bound Encryption (ABE) bypass and anti-VM detection.
- A wide, deliberate target list: 65 cryptocurrency wallet extensions, 16 gaming platforms (Steam, Roblox, Minecraft, Battle.net), 8 AI/developer tools, 9 VPN providers, Discord tokens, and browser-saved credentials and card data.
- A convincing lure: Kynx masks itself behind a fake system update banner, likely distributed via cracked software or ClickFix-style pages, while it runs anti-sandbox checks before exfiltrating data.
- Live infrastructure: We traced its C2 to kynxdev[.]xyz, where it uses single-use tokens with a 5-minute validity window and permanent IP bans for invalid requests.
Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.
The full report can be found here.
Related
This entry was posted on August 8, 2026 at 4:03 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools
Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow.
Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.
What STRU Discovered:
Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.
The full report can be found here.
Share this:
Like this:
Related
This entry was posted on August 8, 2026 at 4:03 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.