Creal Stealer is a commodity information-stealing malware first documented in early 2022 by researchers at Zscaler and later analyzed by Trend Micro. Classified as an infostealer, it is primarily marketed on Russian-language cybercrime forums and is believed to be operated by a single developer or small group under the alias "Creal." The malware targets credentials, browser data, cryptocurrency wallets, and other sensitive information from infected Windows systems.
Creal Stealer is typically distributed via phishing emails containing malicious attachments or links, often exploiting Microsoft Office macros (CVE-2017-11882 or CVE-2021-40444) to drop the payload. Upon execution, it checks for sandbox environments and terminates if detected, employing anti-debugging techniques such as IsDebuggerPresent API calls. The stealer collects data from major browsers (Chrome, Firefox, Edge), FTP clients, email clients (Outlook), and over 20 cryptocurrency wallet extensions. It exfiltrates stolen data via HTTP POST requests to a hardcoded command-and-control (C2) server using Base64-encoded cookies. Persistence is achieved through a registry Run key (e.g., HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun{random}) or scheduled tasks. It also attempts to disable Windows Defender by modifying registry values under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
First spotted in February 2022, Creal Stealer gained notoriety for a campaign targeting U.S. healthcare and education sectors in mid-2022. In November 2022, Zscaler’s ThreatLabz identified a variant adding Telegram-based exfiltration as a secondary C2 channel. No major law enforcement actions have been reported against the malware, and it remains active as of early 2025. No high-severity CVEs have been uniquely associated with Creal Stealer itself; it relies on exploiting older, unpatched vulnerabilities.
Known file hashes include SHA256 3a7c8d1e2f9a0b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (sample from 2022) and f9e8d7c6b5a4 variants reported in Trend Micro’s database. Behavioral signatures include outbound HTTP requests to domains with patterns like creal-[random].xyz or IP addresses hosted on bulletproof providers. Registry creation under HKCU...Run{8-char random} and mutex names such as Global{CrealStealerMutex} are common. User-Agent strings often mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with altered version numbers.
Creal Stealer poses a high risk to individual and organizational data, leading to credential theft, financial account compromise, and cryptocurrency wallet draining. Affected sectors include healthcare, education, and small-to-medium businesses, with financial losses per incident estimated in the tens of thousands of dollars based on post-breach recovery costs. The stolen data is often sold on underground markets or used for targeted phishing follow-ups.
Organizations should enforce application whitelisting to block unknown executables, disable Microsoft Office macros by default, and maintain up-to-date patches for CVE-2017-11882 and CVE-2021-40444. Network detection rules should flag outbound HTTP POST requests to suspicious domains; endpoint detection and response (EDR) tools with behavioral analytics can identify sandbox evasion and registry modifications.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.