Netskope Threat Labs

RisePro

ATP Sandbox Adv. Heuristics

RisePro is an information stealer that targets credentials, browser data, and cryptocurrency wallets on infected systems. It emerged from the same criminal ecosystem as other pay per install operations, and its operators distribute it through fake software, malvertising, and loader chains. Stolen data flows to control panels where crews use it for account takeover or sell it onward, and its affiliate model keeps the family's infrastructure persistent.

First seen
August 2023
Last seen
September 2026
RiseProStealerRisepro
Alert Name
ByteCode-MSIL.Spyware.Risepro
ByteCode-MSIL.Trojan.RiseProStealer
Win32.Spyware.Risepro
Win32.Trojan.RisePro
Win32.Trojan.RiseProStealer
Win64.Trojan.RiseProStealer