August Stealer - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:28:54 UTC Home > List all groups > List all tools > List all groups using tool August Stealer Tool: August Stealer Names August Stealer Category Malware Type Info stealer, Credential stealer, Exfiltration Description (Proofpoint) During the month of November, Proofpoint observed multiple campaigns from TA530 - an actor we have noted for their highly personalized campaigns - targeting customer service and managerial staff at retailers. These campaigns utilized “fileless” loading of a relatively new malware called August through the use of Word macros and PowerShell. August contains stealing functionality targeting credentials and sensitive documents from the infected computer. Information Malpedia AlienVault OTX Last change to this tool card: 13 May 2020 Download this tool card in JSON format All groups using tool August Stealer Changed Name Country Observed APT groups   TA530 [Unknown] 2016-Nov 2016   1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=43a1e38a-c143-443b-a501-ec2299589720 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=43a1e38a-c143-443b-a501-ec2299589720 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=43a1e38a-c143-443b-a501-ec2299589720 Page 2 of 2