Epsilon Stealer is an information-stealing malware first publicly documented in July 2023 by the BlackBerry Research & Intelligence Team. It is written in C++ and operates as a commercial stealer sold on cybercrime forums, belonging to the stealer category of malware that targets credentials, cryptocurrency wallets, and browser data. The threat actor behind its development is tracked as "Enemy" on Russian-language underground markets.
Epsilon Stealer uses a multi-stage infection chain: initial access is gained via phishing emails containing malicious ZIP archives or via trojanized software downloads. Once executed, it drops a DLL payload that uses process hollowing to inject into legitimate processes such as svchost.exe. The malware establishes persistence by creating a scheduled task named "WindowsUpdateTask" and adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For C2 communication, it employs HTTPS POST requests to hardcoded URLs with a User-Agent string mimicking Chrome (Mozilla/5.0 Windows NT 10.0; Win64; x64 AppleWebKit/537.36). Evasion techniques include encrypting its strings with XOR and using Sleep calls to delay analysis. It also checks for sandbox environments by detecting debugger presence (IsDebuggerPresent API) and virtual machine artifacts (presence of vmtoolsd.exe).
First appearing in June 2023 on the XSS cybercrime forum, Epsilon Stealer was advertised as a "lifetime" stealer for $59. In October 2023, the malware was used in a campaign targeting cryptocurrency users in Southeast Asia, distributing the payload via fake MetaMask browser extensions. No CVEs are directly associated, but the malware leverages the CVE-2023-38831 WinRAR vulnerability for initial delivery in select campaigns. No law enforcement actions have been reported against the operator as of early 2025.
Known file hashes include SHA256 2a3e8f7c...1b4d (from BlackBerry report). Behavioral indicators: the malware writes a file named "chrome_auto_export" to %TEMP% and creates the mutex "GlobalEPSILON_STEALER_MUTEX". Network IOCs include POST requests to api.epsilon[.]pw and the User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.110 Safari/537.36". Registry keys created: HKCUSoftwareMicrosoftWindowsCurrentVersionRunEpsilonUpdater.
Epsilon Stealer exfiltrates credentials from 85+ applications, including Chrome, Edge, and Outlook, as well as data from 40+ cryptocurrency wallets (e.g., Exodus, Electrum). The primary impact is credential theft leading to account takeovers and cryptocurrency theft; the BlackBerry report estimates over 500 victims globally in its first three months, primarily in the finance and retail sectors. Financial losses from crypto theft have been reported as low, with no major public breach attributed.
Defenders should block execution of unsigned binaries from email attachments, deploy YARA rules matching the Epsilon Stealer mutex and registry keys (e.g., rule Epsilon_Stealer from BlackBerry's GitHub), and enforce application allowlisting with Microsoft Defender for Endpoint. Email filtering should flag attachments with double extensions (e.g., invoice.pdf.exe) used in phishing campaigns.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.