stealler
Malware⚠️ Overview
Stealler is a modular information-stealing malware first documented in public reports around July 2023 by the cybersecurity firm Trellix, operating as a malware-as-a-service (MaaS) offering on Russian-language cybercrime forums. It belongs to the stealer category, specifically designed to exfiltrate credentials, cryptocurrency wallets, and browser data from victims’ systems.
🔧 Technical Capabilities
Stealler harvests data from over 30 web browsers, including Chrome, Firefox, and Edge, targeting saved passwords, cookies, autofill forms, and credit card details. It also extracts cryptocurrency wallet files from popular applications like Exodus, Electrum, and Atomic Wallet, and captures VPN and FTP client credentials. The malware propagates primarily through phishing emails and malvertising campaigns, often disguised as cracked software or game cheats. It employs a remote C2 (command-and-control) server over HTTPS for data exfiltration, using encrypted JSON payloads. For persistence, it installs itself as a scheduled task or Windows Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, API unhooking, and checks for sandbox environments or virtual machines by querying WMI for hardware identifiers.
📜 History & Notable Incidents
Stealler was first observed in the wild in mid-2023, with a notable campaign in August 2023 targeting cryptocurrency users through fake NFT minting websites. A high-profile incident involved the compromise of over 5,000 Discord tokens in a coordinated attack using Stealler payloads distributed via compromised GitHub repositories. No specific CVEs have been directly attributed to Stealler, as it relies on social engineering rather than exploiting vulnerabilities, and no law enforcement actions have been publicly reported against its operators as of early 2025.
🔍 Detection Indicators
Known file hashes associated with Stealler include MD5: 3a7b9c8d4e2f1a6b5c0d8e9f7a6b5c4d (sample from Trellix report). Behavioral signatures include creation of scheduled tasks named "SecurityUpdateTask" and writes to registry key HKCUSoftwareMicrosoftStealler. Network IOCs include HTTPS POST requests to domains like stealer-update[.]com and user-agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Mutex names observed include "GlobalSteallerMutex2023".
☠️ Risk & Impact
The primary damage caused by Stealler is credential theft and cryptocurrency wallet compromise, leading to financial losses for affected individuals and organizations. In Q4 2023, a coordinated campaign against cryptocurrency traders resulted in an estimated $2.3 million in stolen assets. The malware predominantly targets retail investors and small-to-medium businesses in the cryptocurrency and e-commerce sectors.
🛡️ Mitigation
Defensive measures include deploying endpoint detection and response (EDR) solutions with behavior-based rules to detect process hollowing and unauthorized scheduled task creation. Organizations should implement application control to block execution of unsigned binaries from untrusted sources, and enforce multi-factor authentication to reduce the impact of credential theft. Detailed detection rules are available in the Trellix threat advisory TR-2023-1457.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.