Netskope Threat Labs

Limitail

ATP Sandbox Adv. Heuristics

Limitail is an information stealer known from detection names such as Infostealer.Limitail that collects confidential information from infected Windows systems. It copies itself into system folders, captures screenshots, and sends stolen data to its operators, and it typically reaches a system after other malware drops it or a user downloads it from a malicious site. Detections under this name indicate that an implant gathered data from the machine, so responders should treat exposed credentials as compromised.

First seen
April 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Infostealer.Limitail
Email-MIME.Infostealer.Limitail
Text.Infostealer.Limitail
Win32.Infostealer.Limitail
Win64.Infostealer.Limitail