Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home DarkWeb News & Services

Meduza Stealer Developers Arrested in Russia

🇷🇺 Russia - Meduza Stealer Developers Arrested

October 31, 2025
Reading Time: 2 mins read
Meduza Stealer Developers Arrested in Russia

Russian authorities, led by the Ministry of Internal Affairs (MВД) with support from Rosgvardia forces, have arrested three individuals in the Moscow region. The suspects are described as young IT specialists and are accused of being the creators and distributors of the Meduza Stealer infostealer malware.

The investigation was reportedly triggered after the group violated the primary unspoken rule of Russian-based cybercrime: do not attack domestic targets. In May 2025, the group allegedly used their own malware to breach a government institution in the Astrakhan region, siphoning protected official data to their servers. This local attack is believed to have prompted the swift law enforcement operation.

A criminal case has been opened under Part 2 of Article 273 of the Russian Criminal Code, which covers the creation, use, and distribution of malicious software. Authorities seized computer equipment, mobile devices, and bank cards during the raids.

Meduza Stealer emerged in June 2023 and was operated as a Malware-as-a-Service (MaaS). It was marketed on cybercrime forums and Telegram as a superior alternative to established stealers like Redline, Raccoon, and Vidar. Subscription prices were approximately $199 per month or $1,199 for lifetime access.

The malware was specifically coded to avoid execution if it detected a system located in Russia or other Commonwealth of Independent States (CIS) countries. The developers’ decision to override this feature for the Astrakhan attack led directly to their arrests. It is important to note that the Meduza Stealer (infostealer) is not related to the notorious Medusa ransomware group.

The allegedly compromised data, which the stealer was designed to harvest from victims, includes:

  • Browser Data: Login credentials, cookies, browsing history, and autofill data from over 100 browsers (including Chrome, Firefox, and Edge).
  • Cryptocurrency: Wallet files, seeds, and registry data from over 100 cryptocurrency wallets, including browser extensions like MetaMask and desktop apps like Exodus.
  • Password Managers: Data from popular managers such as 1Password, LastPass, Bitwarden, and KeePassXC.
  • 2FA Clients: Data from two-factor authentication extensions like Authenticator and Authy.
  • Application Data: Credentials from messaging apps (Telegram, Discord), gaming platforms (Steam), and VPN clients (OpenVPN).
  • System Profiling: Hardware details, IP address, timezone, and screenshots for victim profiling.
Tags: ArrestArticle 273AstrakhancybercrimeinfostealerMalware-as-a-ServiceMeduza StealerMVDRosgvardiaRussia
ShareTweet

Related Posts

BreachForums Announces VECT Partnership and Security Updates
DarkWeb News & Services

BreachForums Announces VECT Partnership and Security Updates

April 16, 2026
ShinyHunters Telegram Update Claims Second Leader Arrested
DarkWeb News & Services

ShinyHunters Telegram Update Claims Second Leader Arrested

February 5, 2026
INC Ransomware Breaches Wall Street English – 3.5TB Data Leaked
DarkWeb News & Services

INC Ransomware Breaches Wall Street English – 3.5TB Data Leaked

December 25, 2025
SLSH Announces Return and Teases New Website for November 24
DarkWeb News & Services

SLSH Announces Return and Teases New Website for November 24

November 21, 2025
Operation Endgame Takedown Hits Rhadamanthys and VenomRAT
DarkWeb News & Services

Operation Endgame Takedown Hits Rhadamanthys and VenomRAT

November 13, 2025
Exclusive: Everest Ransomware Group Interview on Collins Aerospace Breach
DarkWeb News & Services

Exclusive: Everest Ransomware Group Interview on Collins Aerospace Breach

November 6, 2025
Next Post
Vexels Data Breach Exposes 820K Users

Vexels Data Breach Exposes 820K Users

Gateworks Corporation Data Breach Exposes Partner Documents

Gateworks Corporation Data Breach Exposes Partner Documents

Recommended Stories

Iran’s IRGC Surveillance Database Allegedly Leaked – Exposing Monitoring of Activists

Iran’s IRGC Surveillance Database Allegedly Leaked – Exposing Monitoring of Activists

August 25, 2025
Alleged IDOR Vulnerability in Al Rajhi Bank’s APIs for Sale

Alleged IDOR Vulnerability in Al Rajhi Bank’s APIs for Sale

September 29, 2024
BeachGuide.com Email Database Leak Affects Over 92,000 Users

BeachGuide.com Email Database Leak Affects Over 92,000 Users

November 28, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?