Octalyn: The Stealer Hidden in Plain Sight

Amber | Attack Report
Download PDF

The Octalyn Forensic Toolkit, though disguised as an educational tool, is actually a stealthy credential stealer that preys on unsuspecting users. Shared openly on GitHub, it lures in low-skilled actors with a simple builder that creates custom data-stealing payloads using just a Telegram bot token and chat ID. Once deployed, the malware silently steals sensitive information like browser cookies, saved passwords, Discord tokens, crypto wallets, VPN configs, and more organizing everything neatly into folders before zipping it up and sending it back to the attacker via Telegram. What makes Octalyn especially dangerous is how easy it is to use and how convincingly it hides behind a “forensic research” narrative, turning a lightweight GitHub tool into a powerful vehicle for data theft and system compromise.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs