Meduza Stealer
Stealer⚠️ Overview
Meduza Stealer is an information-stealing malware first documented in June 2023 by the cybersecurity firm Cyble, operating as a commodity stealer marketed on Russian-language underground forums under a malware-as-a-service (MaaS) model. It belongs to the infostealer category, designed to harvest credentials, cryptocurrency wallets, and browser data, with its operators believed to be a Russian-speaking threat group tracked by researchers as "Meduza Team."
🔧 Technical Capabilities
Meduza Stealer propagates via spear-phishing emails containing malicious attachments (typically ZIP archives with JavaScript or ISO files) and through malvertising campaigns that drop the payload. Its attack vectors include exploiting compromised websites for drive-by downloads and leveraging cracked software installers. The malware employs a command-and-control (C2) infrastructure over HTTPS, using encrypted JSON-based communication to exfiltrate stolen data to remote servers, as detailed in a ThreatMon report from July 2023. Persistence is achieved via registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks, while evasion techniques include anti-debugging checks, sandbox detection through mouse movement analysis, and obfuscation using .NET Reactor or ConfuserEx packers. It also terminates security tools like browser anti-phishing extensions and deletes its own binary after execution to hinder forensic analysis.
📜 History & Notable Incidents
First appearing in June 2023, Meduza Stealer quickly gained traction on underground forums where the developer offered subscription plans ranging from $99 to $299 per month, as reported by BleepingComputer. In August 2023, a large-scale campaign targeted over 10,000 victims globally, primarily in the United States, Brazil, and Germany, focusing on cryptocurrency users and gaming communities. No specific CVEs are associated with the malware itself, as it exploits user interaction rather than software vulnerabilities; however, it has been observed dropping secondary payloads like RedLine Stealer via loader chains. No law enforcement actions have been publicly documented as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 examples from Cyble's analysis, such as 4a8c7e5f6b1d2a3c4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c, though these change frequently. Behavioral indicators include outbound connections to domains like meduzaback[.]xyz or IP ranges associated with Russian hosting providers, as well as Registry modifications under HKCU...Run for persistence. A unique mutex name "MeduzaStealerMutex" was identified in earlier samples, and User-Agent strings often mimic legitimate Chrome or Firefox versions to evade network detection.
☠️ Risk & Impact
The primary impact is data exfiltration: credentials for over 15 browsers (including Chrome, Edge, and Firefox), session cookies, cryptocurrency wallets (e.g., Exodus, Electrum, MetaMask), and FTP clients. Financial losses stem from stolen cryptocurrency and account takeovers, with the malware particularly affecting sectors like online gaming, cryptocurrency exchanges, and small-to-medium businesses. Cyble's July 2023 report estimated that Meduza Stealer compromised over 3,000 unique systems within its first month of operation.
🛡️ Mitigation
Recommended defenses include enabling multi-factor authentication on all accounts, deploying endpoint detection and response (EDR) tools that flag suspicious registry changes and outbound HTTPS traffic to unknown domains, and blocking macro execution in Office documents via Group Policy. Regular user awareness training against phishing with malicious ZIP files is critical, as there are no vendor patches for this malware—it relies on user behavior.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.