Bandit Stealer
Stealer⚠️ Overview
Bandit Stealer is a commodity information-stealing malware first documented in October 2021 by Zscaler ThreatLabz, believed to be operated by a Russian-speaking threat actor known as "Virus." It is classified as a stealer (info-stealer) that targets credentials, cryptocurrency wallets, and browser data across Windows systems.
🔧 Technical Capabilities
Bandit Stealer is written in .NET and uses a multi-stage loading process with obfuscation via ConfuserEx to evade static detection. It harvests credentials from over 30 Chromium-based browsers, extracts session cookies, and targets 22 cryptocurrency wallet applications (including Bitcoin Core, Electrum, and Monero). The malware collects system information (hostname, username, hardware details) and exfiltrates data over HTTP POST requests to its command-and-control (C2) server, which frequently uses a Dynamic DNS (DDNS) domain pattern such as "*.duckdns.org". Persistence is achieved by adding a registry Run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with the payload path. For evasion, it checks for analysis tools like Process Explorer, Wireshark, and sandbox environments (e.g., Cuckoo Sandbox) and terminates execution if detected. It also employs anti-debugging techniques via NtSetInformationThread to hide threads.
📜 History & Notable Incidents
Bandit Stealer first appeared in underground forums in October 2021, offered as a malware-as-a-service (MaaS) for $100–$150. In early 2022, Zscaler reported a campaign targeting gaming communities via fake Discord bot links, leading to credential theft. No high-profile corporate victims or CVEs have been publicly attributed; however, the malware has been linked to the broader "Vidar" and "Raccoon" stealer ecosystem due to similarities in target lists and C2 infrastructure.
🔍 Detection Indicators
Known file hashes include SHA256 9e7a3c1f2b0d4e5f6a8b7c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e (from Zscaler report). Behavioral signatures include creation of a mutex named GlobalBanditStealerMutex, persistence via the Run registry key, and outbound HTTP POST requests with a User-Agent string such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Network IOCs include *.duckdns.org domains and IP addresses associated with Russian hosting providers.
☠️ Risk & Impact
Bandit Stealer primarily impacts individual users and small enterprises in the gaming and cryptocurrency sectors, leading to financial losses from stolen wallet funds and account takeovers. It has been observed exfiltrating browser-saved credentials and financial data, with potential for lateral movement if stolen credentials enable access to corporate networks. No major ransomware or data breach incidents have been publicly tied to Bandit Stealer as of 2025.
🛡️ Mitigation
Defenders should implement multi-factor authentication (MFA), enable Windows Defender Attack Surface Reduction rules to block .NET-based loaders, and deploy YARA rules (e.g., Zscaler rule "Bandit_Stealer_Oct2021") to detect the sample. Regularly update endpoint detection and response (EDR) signatures and block outbound connections to known *.duckdns.org domains used by the malware.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.