MercurialGrabber is an information stealer malware first identified in mid-2024 by Infosecurity Magazine, operated by a Russian-speaking threat actor known as Mercurial. It belongs to the stealer category, targeting browser credentials, cryptocurrency wallets, and session cookies through a Delphi-compiled payload.
MercurialGrabber propagates via phishing emails with malicious attachments or through malvertising campaigns redirecting users to exploit kits. It employs a C2 infrastructure using HTTP POST requests to exfiltrate stolen data, with command-and-control servers hosted on bulletproof hosting providers. Persistence is achieved through registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation of strings using XOR encoding, anti-debugging checks via IsDebuggerPresent, and dynamic API resolution to avoid static detection. The malware also leverages process hollowing to inject into legitimate processes like explorer.exe or notepad.exe to evade behavioral analysis.
First discovered in June 2024 by researchers at Cyble, MercurialGrabber gained attention in a campaign targeting crypto holders through fake NFT marketplace sites. No major CVEs are directly linked; instead, it exploits human vulnerabilities via social engineering. Law enforcement actions have not been publicly reported as of early 2025, but several takedowns of associated C2 domains have been documented by BleepingComputer.
Known file hashes include SHA256: d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5 (from VirusTotal). Behavioral signatures include creation of %TEMP%Mercurial directory, HTTP POST to IPs in the 185.xxx.xxx.xxx range, and registry key HKCU...RunWindowsUpdate. User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) MercurialGrabber/1.0.
MercurialGrabber primarily causes credential theft and cryptocurrency wallet compromise, leading to financial losses for individuals and small businesses. The stealer has been observed targeting the cryptocurrency sector, with reports from Cyble indicating over $500,000 in stolen crypto assets traced to a single campaign in August 2024.
Defenders should implement email filtering for phishing attachments, enable Microsoft Defender for Endpoint with ASR rules to block LSASS credential theft, and deploy YARA rules detecting the MercurialGrabber XOR key pattern (0xAB). Regular patching of browsers and disabling macros in Office documents are recommended.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.