
Executive Summary
Operators linked to RisePro announced a new malware update with features aimed at evading cookie protections, expanding local file collection, improving credit card theft, and adding an optional cryptolocker module.
The information comes from an official channel associated with the malware. Based on the available information, there is no validated technical sample or independent analysis confirming the actual functionality of the announced capabilities. For that reason, they should be treated as operator claims rather than verified features.
The announcement is relevant because it shows that RisePro is moving toward stronger support against new browser protections, greater flexibility for local data theft, increased pressure against Windows Defender, and a possible expansion from stealer functionality toward destructive or extortion-oriented features.
Key Judgments
- RisePro claims to have incorporated a module to evade cookies protected by DBSC, a technology designed to reduce abuse of stolen cookies.
- The announcement adds an optional cryptolocker, which could expand the malware’s use beyond traditional information theft.
- The update declares new collection functions targeting desktop and document directories, along with improvements in credit card capture.
- Repeated mentions of “Cleaned WD 10/11 + Cloud” show that evasion against Windows Defender remains a central sales argument.
- The announced capabilities require independent technical validation before being treated as confirmed.
What Happened
RisePro published an update claiming to have implemented a module for evading cookies protected by DBSC, available according to the message for Chrome 147 on Windows. DBSC is a protection designed to reduce session hijacking through stolen cookies by binding the session to the user’s device.
The announcement also mentions the addition of a cryptolocker configurable with custom keys, an optional file grabber for desktop directories and the “My Documents” folder, improvements in credit card collection with support for different encodings, and a new cleanup against Windows Defender on Windows 10/11 and its cloud component.
This update follows a series of changes communicated during April, including improvements in virtual machine detection, an integrated Windows Defender scanner, active window title tracking from the remote terminal, updated support for Edge, Brave, and beta Chrome variants, Google cookie recovery from browser tokens, changes to the screenshot mechanism, and fixes affecting the loader, file search, WinSCP, and link encryption.
Operational Assessment
The most important signal is the reference to DBSC. Stealers depend heavily on the theft of cookies, tokens, and browser data to monetize access, bypass MFA, or feed credential markets. If session protections reduce the value of those cookies outside the original device, malware operators need to adapt techniques, collection flows, or exploitation models.
Although the bypass announced by RisePro is not confirmed, its appearance as a commercial argument indicates that DBSC is already being treated by the criminal ecosystem as a relevant barrier. This does not mean the protection is broken; it means operators are trying to present themselves as capable of preserving value against newer defensive controls.
The optional cryptolocker also deserves attention. RisePro is primarily known as an infostealer, but the addition of destructive or extortion-oriented encryption may partially change its operational reading. It does not automatically turn RisePro into ransomware, but it does suggest a functional expansion toward scenarios where information theft can be combined with direct damage or additional pressure against the victim.
The improvements in local collection, credit card theft, and support for different browsers reinforce the malware’s classic orientation: extracting useful information, increasing compatibility, and improving monetization. Repeated references to Windows Defender also indicate that evasion remains central to the product’s positioning toward buyers and operators.
Intelligence Significance
RisePro’s announced update reflects a broader trend in the infostealer ecosystem: rapid adaptation to defensive changes, integration of modular functions, and expansion toward capabilities that combine theft, monitoring, evasion, and possible extortion.
The intelligence value is not in assuming that every function works as announced, but in observing which capabilities are being sold as differentiators. In this case, the operator’s message points to three priorities: continuing to capture useful data despite new browser protections, increasing the volume of information collected from the endpoint, and improving survivability against Windows-integrated defenses.
For defensive teams, the announcement reinforces the need to monitor behaviors associated with cookie and token theft, anomalous access to browser profiles, mass collection of user files, manipulation of financial data, execution of payloads with destructive capability, and evasion against local controls.
Analytical Closing
RisePro’s announcement should not be treated as automatic validation of its capabilities, but it is a relevant signal of the malware’s evolution. The mention of DBSC shows that stealer operators are reacting to new session defenses. The addition of an optional cryptolocker and improvements in local collection expand the malware’s functional profile beyond traditional credential theft. Until a sample or independent technical validation is available, the most prudent reading is to observe this update as a statement of direction: RisePro is attempting to remain competitive in a crimeware market where evasion, browser theft, local extraction, and extortion pressure are increasingly converging.
Explore 2C-INT
Go deeper into criminal, extremist and hybrid structures through an intelligence environment built around context.
Get new publications
Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.