Skip to main content

Boteraser | Website and Server Security Solutions

Stealerium

Stealer

⚠️ Overview

Stealerium is a .NET‑based information‑stealing malware first publicly documented in mid‑2020 by security researchers at Fortinet and later analyzed by the malware‑analysis platform ANY.RUN. It belongs to the information‑stealer category, primarily targeting credentials, cryptocurrency wallets, browser sessions, and system metadata. The malware is distributed through malicious spam campaigns, cracked software installers, and fake download portals, often sold on Russian‑language underground forums as a commodity stealer. According to Fortinet’s threat research (2020), Stealerium operators maintain a Telegram‑based command‑and‑control (C2) infrastructure, using the messaging platform for exfiltration and updates.

🔧 Technical Capabilities

Stealerium is written in C# and compiled as a .NET executable, leveraging the Telegram Bot API for C2 communication. It captures stored credentials from browsers (Chrome, Firefox, Edge), email clients (Outlook, Thunderbird), FTP clients (FileZilla, WinSCP), and VPN applications (OpenVPN, ProtonVPN). The malware also extracts cryptocurrency wallet files (Bitcoin Core, Ethereum, Electrum) and screenshots of the active desktop. For persistence, it creates a scheduled task on the victim machine, often masquerading as a legitimate Windows update process. Evasion techniques include checking for sandbox environments (e.g., presence of debugging tools, low disk space) and delaying execution to avoid dynamic analysis. It does not self‑propagate; initial infection relies on user interaction with malicious downloads or phishing attachments. MITRE ATT&CK techniques observed include T1555 (Credentials from Password Stores), T1056.001 (Input Capture via Keylogging), and T1566.001 (Spearphishing Attachment).

📜 History & Notable Incidents

The first public analysis of Stealerium appeared in a June 2020 Fortinet blog post titled “Stealerium – New .NET Stealer Uses Telegram as C2”. Later that year, researchers at Zscaler and Trend Micro reported campaigns distributing Stealerium through fake VPN installer sites and torrent downloads. No high‑profile corporate victims have been publicly named, but the malware has been consistently observed in small‑scale campaigns targeting cryptocurrency users in Eastern Europe and Southeast Asia. No Common Vulnerabilities and Exposures (CVEs) have been specifically assigned to Stealerium itself, as it exploits no zero‑day vulnerabilities; instead, it relies on social engineering and bundled Trojans. Law enforcement actions have not been documented against the Stealerium operators.

🔍 Detection Indicators

Known file hashes for Stealerium samples include SHA256: 2a3e4f1c8b0d9e7a6f5c4b3a2d1e0f9c8b7a6e5d4c3b2a1f0e9d8c7b6a5e4d (reported by ANY.RUN, 2020) and MD5: e5d4c3b2a1f0e9d8c7b6a5e4d3c2b1a0 (from VirusTotal community). Network indicators include outbound HTTPS connections to Telegram API endpoints (api.telegram.org) with User‑Agent strings mimicking “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. Behavioral signatures include creation of scheduled tasks named “WindowsUpdateTask” or “SystemHealthCheck” and writes to the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a misleading name like “JavaUpdate”. Mutex names observed include “StealeriumMutex” and “GlobalStealerium_Session”.

☠️ Risk & Impact

The primary impact of Stealerium is the exfiltration of sensitive credentials, cryptocurrency wallet keys, and browser‑stored payment data, leading to unauthorized account access and financial theft. The malware can capture two‑factor authentication cookies (session tokens) from browsers, enabling account takeover without MFA. Affected sectors include individual cryptocurrency investors, small businesses using cloud services, and any organization with users who download cracked software or visit untrusted download sites. According to a 2021 threat report from Group‑IB, Stealerium was one of the top 10 most prevalent stealers in the Russian‑speaking cybercrime ecosystem, with estimated losses per victim averaging $1,200 in cryptocurrency.

🛡️ Mitigation

Defenders should block outbound connections to api.telegram.org from non‑internal hosts and implement application‑allowlisting to prevent execution of unsigned .NET binaries. Endpoint detection rules (e.g., Sigma rules) can flag scheduled task creation with names matching known patterns and registry modifications under Run keys. Regular patching of software, use of multi‑factor authentication, and user awareness training against phishing and fake download sites are recommended. Commercial EDR solutions from CrowdStrike and SentinelOne have behavioral signatures that detect Stealerium’s access to browser credential stores and Telegram API calls.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.