SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools

Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow. 

Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.

What STRU Discovered:

  • AI-assisted development: The developer openly credits Gemini for helping build the malware, including its App-Bound Encryption (ABE) bypass and anti-VM detection.
  • A wide, deliberate target list: 65 cryptocurrency wallet extensions, 16 gaming platforms (Steam, Roblox, Minecraft, Battle.net), 8 AI/developer tools, 9 VPN providers, Discord tokens, and browser-saved credentials and card data.
  • A convincing lure: Kynx masks itself behind a fake system update banner, likely distributed via cracked software or ClickFix-style pages, while it runs anti-sandbox checks before exfiltrating data.
  • Live infrastructure: We traced its C2 to kynxdev[.]xyz, where it uses single-use tokens with a 5-minute validity window and permanent IP bans for invalid requests.


Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.

The full report can be found here

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading