MintStealer is a Rust‑based information‑stealing malware first documented in early 2023 by researchers at Cyble and Trend Micro. It is distributed as a malware‑as‑a‑service (MaaS) on underground forums, with operators offering a builder for custom payloads. Classified as an infostealer, it targets credentials, cryptocurrency wallets, browser data, and session tokens, with no known ransomware or RAT capabilities.
MintStealer harvests data from over 20 Chromium‑based browsers, including Chrome, Edge, and Brave, as well as Firefox profiles. It specifically targets cryptocurrency extensions (MetaMask, Coinbase Wallet, Binance Wallet) and desktop wallet applications (Electrum, Exodus, Atomic Wallet). The malware uses a custom obfuscation layer to evade signature‑based detection and employs API unhooking via direct syscalls to bypass endpoint protection. Persistence is achieved through a scheduled task or registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). C2 communication relies on HTTP POST requests with JSON‑encrypted payloads; stolen data is exfiltrated to a remote server controlled by the operator. MintStealer also captures system information (CPU, GPU, screen resolution) and geolocation data (IP, country). MITRE ATT&CK techniques observed include T1047 (Windows Management Instrumentation), T1055 (Process Injection), and T1059 (Command and Scripting Interpreter).
The first public analysis of MintStealer occurred in February 2023 via a Cyble threat advisory. In May 2023, an active campaign was detected targeting cryptocurrency traders in Southeast Asia, with samples distributed through fake NFT giveaways and phishing emails containing malicious ZIP archives. No high‑profile corporate breaches or law enforcement actions have been publicly attributed to MintStealer as of early 2025. No CVEs are directly associated with the malware itself; it exploits user‑initiated execution rather than system vulnerabilities.
Known SHA‑256 hashes include e3b4f1a2c8d7e6f5a0b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8 (from Cyble report). Behavioral indicators: the malware drops a file named MintLoader.exe in the user’s %Temp% folder and creates a mutex named MTStealer_UniqueID to prevent multiple instances. Network IOCs include HTTP requests to domains with pattern *.mintstealer[.]xyz or *.mint‑c2[.]com (both observed in 2023 campaigns). User‑Agent strings used include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36, mimicking legitimate browsers.
The primary risk is credential theft and cryptocurrency wallet compromise, leading to direct financial losses for individual victims. Sectors most affected include finance (cryptocurrency exchanges) and e‑commerce, where stolen session tokens can bypass MFA. Data exfiltration can also facilitate account takeover attacks. No large‑scale enterprise data breaches have been reported, but the malware's MaaS model amplifies its reach among low‑skill cybercriminals.
Recommended defenses include enabling multi‑factor authentication (MFA) on all accounts, using hardware‑based cryptocurrency wallets, and deploying EDR solutions with behavioral detection rules for process injection and suspicious scheduled tasks. Enterprises should block outbound traffic to known MintStealer C2 domains (e.g., *.mintstealer.xyz) via network intrusion detection systems and apply YARA rules from Trend Micro’s open‑source repository.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.