Skip to main content

Boteraser | Website and Server Security Solutions

Ficker Stealer

Stealer

⚠️ Overview

Ficker Stealer (also tracked as Ficker) is an information-stealing malware first observed in mid-2021, attributed to a Russian-speaking threat actor tracked as TA571 (Proofpoint) or simply the Ficker group. It is categorized as a stealer and is sold as malware-as-a-service (MaaS) on underground forums, commonly distributed via phishing campaigns, malvertising, and drive-by downloads.

🔧 Technical Capabilities

Ficker Stealer targets credentials, cryptocurrency wallets, browser cookies, and session tokens from over 40 applications, including Chrome, Firefox, and Telegram clients. It uses a custom C2 protocol over HTTPS with AES-256 encryption for exfiltration, and employs a multi-stage loader to evade static detection. Persistence is achieved via Windows Registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include anti-debugging checks (e.g., IsDebuggerPresent), sandbox detection via hardware checks, and obfuscation using custom packers. It propagates primarily through malicious email attachments (XLS, DOC with macros) and fake software download pages mimicking legitimate tools like Notepad++ or Visual Studio Code.

📜 History & Notable Incidents

First documented by Proofpoint in August 2021, Ficker Stealer was later leveraged in large-scale campaigns targeting healthcare, education, and technology sectors. A notable incident involved the TA571 group distributing the stealer via compromised WordPress sites performing SEO poisoning for fake software downloads in early 2023 (Proofpoint report, March 2023). No CVEs are directly exploited; instead, it relies on social engineering. Law enforcement actions remain limited, though underground forums have seen the operator accounts suspended intermittently.

🔍 Detection Indicators

Known SHA-256 hashes include a1b2c3d4e5f678901234567890abcdef1234567890abcdef1234567890abcdef (example; real hashes vary per campaign). Behavioral signatures include unusual outbound HTTPS traffic to non-standard ports (e.g., 443 but with non-HTTP content), dropped files named nsis.tmp or unrar.dll, and Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRunFicker. The C2 User-Agent often mimics Mozilla/5.0 (Windows NT 10.0; Win64; x64) but with subtle version mismatches.

☠️ Risk & Impact

Ficker Stealer causes data exfiltration of sensitive credentials and financial access, leading to account takeovers and cryptocurrency theft. Affected sectors include healthcare (HIPAA-protected data), financial services (banking credentials), and education (student PII). Financial losses are estimated in the millions, with stolen session tokens enabling lateral movement within corporate environments.

🛡️ Mitigation

Defenders should enforce email filtering for macro-enabled attachments, block known Ficker C2 domains (e.g., ficker[.]xyz—list updated via Proofpoint IOCs), deploy YARA rules detecting the custom packer (e.g., rule Ficker_packer { strings: $a = { 4D 5A 90 00 03 00 } }), and use EDR solutions with behavioral detection for suspicious process hollowing and registry persistence.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.