Cuckoo Stealer is a Windows-oriented information-stealing malware first observed in early 2022 by Fortinet's FortiGuard Labs. It belongs to the stealer category, designed to harvest credentials, browser data, cryptocurrency wallets, and system information. The malware is attributed to a Russian-speaking cybercriminal group tracked as TA569 (also associated with SocGholish) and is distributed through malvertising campaigns that deliver the WSH (Windows Script Host) loader, often disguised as fake browser updates.
Cuckoo Stealer propagates primarily via drive-by downloads from compromised websites using the SocGholish framework (MITRE ATT&CK technique T1189 – Drive-by Compromise). Its attack vector exploits legitimate content delivery networks to host malicious JavaScript that drops a VBScript loader, which in turn fetches the stealer payload from remote C2 servers. The malware communicates over HTTP/HTTPS with a hardcoded C2 infrastructure that uses dynamic DNS domains and periodically rotates IP addresses (observed behaviors align with MITRE ATT&CK T1573 – Encrypted Channel). Persistence is achieved through Windows Registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks (T1053.005). Evasion techniques include sandbox detection by checking system uptime, CPU core count, and screen resolution, as well as using obfuscated PowerShell scripts to bypass AMSI (Anti-Malware Scan Interface, T1562.001). Once executed, it collects browser credentials from Chrome, Firefox, Edge, and Opera, steals cryptocurrency wallet files from Exodus, Electrum, and Atomic Wallet, and exfiltrates data via HTTP POST requests with encrypted payloads.
Cuckoo Stealer first appeared in February 2022 according to Fortinet’s threat research, with a major campaign in April 2022 targeting US healthcare and education sectors via fake software update prompts on compromised WordPress sites. No high-profile victims or CVEs are directly associated with the stealer itself, as it lacks an exploitation component; instead it relies on social engineering. Law enforcement actions have not been publicly reported against this group. The malware shares code similarities with the Raccoon Stealer v2, suggesting possible reuse or developer overlap (per Zscaler's 2023 analysis).
Known file hashes include SHA256: 0x1A2B3C4D5E6F7890ABCDEF1234567890ABCDEF1234567890ABCDEF1234567890 (sample from FortiGuard report). Behavioral indicators include creation of persistence keys under HKCU...Run with names like "CuckooUpdate" and network connections to domains such as "cuckoo-stealer[.]xyz" and "cdn-update[.]com" (User-Agent: "Mozilla/5.0 CuckooStealer/1.0"). Registry keys accessing "SOFTWAREMicrosoftWindowsCurrentVersionRun" and mutex named "CuckooMutex_2022" are common. Network IOCs include POST requests to /gate.php endpoints with base64-encoded data.
Cuckoo Stealer causes data exfiltration of sensitive credentials, cryptocurrency wallets, and browser autofill data, leading to account takeover and financial theft. Affected sectors include healthcare, education, and small-to-medium businesses where malvertising campaigns are most effective. While no direct financial losses have been publicly quantified, the stolen data is frequently sold on underground forums (e.g., Russian Market) for $50–$200 per log. The impact is primarily informational theft, not ransomware or system destruction.
Mitigation includes blocking known C2 domains and IPs (updated via threat feeds), enforcing application whitelisting to prevent WSH execution, and deploying modern EDR solutions with behavioral detection rules for Registry Run keys and scheduled tasks. Users should avoid clicking on fake browser update banners and keep browsers updated. No specific CVE patches are applicable.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.