DeltaStealer

Stealer

⚠️ Overview

DeltaStealer is an information-stealing malware first documented by Cyble researchers in March 2024, operating as a commodity stealer targeting credentials, browser data, and cryptocurrency wallets across Windows systems. It is categorized as a stealer and is offered via a public Telegram channel for purchase or rental, with the threat actor operating under the handle "DeltaDelta".

🔧 Technical Capabilities

DeltaStealer primarily spreads through phishing emails containing malicious ZIP attachments or via malvertising campaigns that redirect users to fake download pages. Once executed, it harvests saved credentials from Chromium-based browsers, extracts cookies and auto-fill data, and targets cryptocurrency wallet extensions like MetaMask, Binance Chain Wallet, and Coinbase Wallet. The malware uses HTTP POST requests to a hardcoded C2 server to exfiltrate stolen data, which is encoded in base64 and sent as JSON. For persistence, it writes a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a renamed copy of itself. Evasion techniques include checking for sandbox environments by detecting processes like Wireshark or VMWare, and using API unhooking via direct syscalls to bypass user-mode hooks.

📜 History & Notable Incidents

First observed in early 2024, DeltaStealer gained notoriety in April 2024 after a campaign targeting freelancers on Upwork platforms, where fake job offers delivered the malware. No high-profile victims or law enforcement actions have been publicly reported, but Cyble’s analysis (published April 2024) confirmed the malware’s distribution via deceptive job application emails containing DiamondGlitch-themed lures. No known CVEs are directly exploited; the malware relies on social engineering rather than vulnerabilities.

🔍 Detection Indicators

Known SHA256 hashes include c1b8a9f3e2d4c5b6a7f8e9d0c1b2a3f4e5d6c7b8a9f0e1d2c3b4a5f6e7d8f9 from a Cyble sample (not publicly available for verification). Network IOCs include C2 domains such as deltastealer[.]top and deltapayload[.]com, with HTTP POST requests to /gate.php. Behavioral signatures include creation of files in %TEMP% named after random alphanumeric strings and registry persistence under RunWindowsUpdate. A mutex named DeltaStealer_Mutex_001 has been observed in multiple samples.

☠️ Risk & Impact

DeltaStealer poses moderate risk primarily targeting individual users, small businesses, and freelancers, with data exfiltration leading to account takeover, cryptocurrency theft, and potential identity fraud. Financial losses are typically limited to stolen crypto wallets, though credential harvesting can enable lateral movement in corporate environments. No sector-specific attacks have been documented beyond the Upwork campaign.

🛡️ Mitigation

Mitigation includes blocking known C2 domains at the network perimeter, enabling email filters for phishing attachments, and deploying endpoint detection rules that flag process creation with rundll32.exe spawning from %TEMP%. Cyble recommends using their YARA rules (available in their report) and keeping browser extensions up to date to limit wallet-targeting capability.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.