PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025, it targets specific data types and employs a straightforward design, making it accessible for less-skilled attackers. Mitigation strategies include user awareness, antivirus deployment, network monitoring, and secure credential management.

Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flaw – Help Net Security
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flaw Help Net Security


