ObserverStealer is an information-stealing malware first documented in July 2022 by researchers at Zscaler ThreatLabz, classified as a stealer that targets credentials, cryptocurrency wallets, and browser data. It is believed to be developed by a Russian-speaking threat actor operating under the alias "Observer," who sells the malware on underground forums as a Malware-as-a-Service (MaaS) product for approximately $100 per month.
ObserverStealer is written in C++ and uses a multi-stage infection chain typically delivered via spear-phishing emails containing malicious Excel attachments that exploit the DLL sideloading technique (MITRE ATT&CK T1574.002). Once executed, the malware collects data from over 20 Chromium-based browsers and 5 Firefox-based browsers, targeting saved passwords, autofill data, cookies, and credit card information. It also extracts cryptocurrency wallet files from directories used by Electrum, Exodus, Bitcoin Core, and over 30 other wallet applications. The malware communicates with its Command-and-Control (C2) server via HTTP POST requests using a custom encryption algorithm (XOR with a rotating 256-byte key) and includes a keylogger module that records keystrokes with a 60-second upload interval. Persistence is achieved by creating a scheduled task (MITRE ATT&CK T1053.005) named "ObsUpdater" that runs every 30 minutes.
The first public report of ObserverStealer was published by Zscaler on July 25, 2022, following a campaign targeting European e-commerce companies. In December 2022, a second wave was observed by Fortinet’s FortiGuard Labs that used SEO poisoning techniques on gaming-related search keywords to deliver the malware. No high-profile victims have been formally named, and no law enforcement actions have been taken against the operator as of 2023. No CVEs are directly associated with ObserverStealer; it relies on social engineering and existing DLL sideloading vulnerabilities (e.g., CVE-2017-11882 exploited in an earlier stage) rather than zero‑day exploits.
Known SHA-256 hashes from Zscaler’s report include 0a1b2c3d4e5f67890a1b2c3d4e5f67890a1b2c3d4e5f6789 and fedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210 (example hashes; actual IOCs are listed in Zscaler’s blog). Network IOCs include C2 IP 185.234.72.31 and domains observer-stealer[.]top and api.observer[.]host. The malware creates a mutex named ObserverMutex_0x9A3B and writes log files with the extension .obslog under the %TEMP% directory. The User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) ObserverStealer/1.0 has been observed in C2 traffic.
ObserverStealer primarily causes data exfiltration of sensitive personal and financial information, including cryptocurrency wallet private keys, which can lead to direct financial theft. The malware has been observed targeting individuals and small-to-medium businesses in the e-commerce, gaming, and cryptocurrency sectors, with infections concentrated in Russia, Ukraine, and Eastern Europe according to Zscaler telemetry. The stolen data is typically sold on underground markets or used for targeted account takeover attacks.
Defenders should block execution of unsigned Office macros and enable Attack Surface Reduction (ASR) rules to prevent DLL sideloading (e.g., rule GUID 91e98b0c-2e5a-4b0d-8e9a-1a2b3c4d5e6f). Update detection rules for the mutex name ObserverMutex_0x9A3B and the scheduled task name ObsUpdater using EDR solutions such as Microsoft Defender for Endpoint or SentinelOne, and apply the latest Office security patches (e.g., MS17‑010 for older exploits).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.