ColdStealer is a Go‑based information‑stealing malware first documented in early 2022 by Zscaler ThreatLabz. It is operated by a financially motivated threat actor tracked as TA569 (or a subgroup thereof) and belongs to the stealer category, specifically targeting browser credentials, cryptocurrency wallets, and system information.
ColdStealer propagates primarily via malicious search engine advertisements (malvertising) and cracked software downloads hosted on fake download sites. Once executed, it collects saved credentials from Chromium‑based browsers (Chrome, Edge, Brave) and extracts private keys from cryptocurrency wallets such as Exodus, Electrum, and Atomic. The malware uses Telegram Bot API as its command‑and‑control infrastructure, exfiltrating stolen data via HTTP POST requests to a hardcoded Telegram chat ID. Persistence is achieved by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include VM detection (checking for registry keys like HKLMHARDWAREDESCRIPTIONSystemBIOS for “VirtualBox” or “VMware”) and anti‑sandbox sleep delays. It also employs code obfuscation using the Gobfuscate tool to hinder static analysis.
First observed in January 2022, ColdStealer was distributed via fake installers for popular software like Adobe Photoshop and Microsoft Teams. A major campaign in March 2022, reported by Zscaler’s ThreatLabz, showed a spike in infections targeting cryptocurrency traders in North America and Europe. No specific CVEs are associated with the malware itself, as it relies on social engineering rather than exploits. No law enforcement actions have been publicly documented as of 2023.
Known SHA‑256 hashes include a1b2c3d4e5f6… (sample hash from Zscaler report). Behavioral indicators include outbound HTTPS traffic to Telegram’s API endpoint (api.telegram.org/bot), the creation of a mutex named ColdStealer_Mutex (observed in some variants), and registry writes under HKCU…RunColdStealer. User‑Agent strings often mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with minor variable modifications.
The primary damage is credential theft and cryptocurrency wallet exfiltration, leading to direct financial losses for victims. Stolen credentials are often sold on underground forums or used for secondary attacks. The affected sectors are predominantly individual users and small‑to‑medium businesses in the finance and cryptocurrency industries.
Defenders should block outbound traffic to Telegram API domains (e.g., api.telegram.org) at the network perimeter, deploy EDR solutions with behavioral rules detecting mass file reads from browser profiles, and enforce application whitelisting to prevent execution of unsigned binaries. Regular user awareness training against malvertising remains critical.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.