Stealler is a modular information-stealing malware first documented in public reports around July 2023 by the cybersecurity firm Trellix, operating as a malware-as-a-service (MaaS) offering on Russian-language cybercrime forums. It belongs to the stealer category, specifically designed to exfiltrate credentials, cryptocurrency wallets, and browser data from victims’ systems.
Stealler harvests data from over 30 web browsers, including Chrome, Firefox, and Edge, targeting saved passwords, cookies, autofill forms, and credit card details. It also extracts cryptocurrency wallet files from popular applications like Exodus, Electrum, and Atomic Wallet, and captures VPN and FTP client credentials. The malware propagates primarily through phishing emails and malvertising campaigns, often disguised as cracked software or game cheats. It employs a remote C2 (command-and-control) server over HTTPS for data exfiltration, using encrypted JSON payloads. For persistence, it installs itself as a scheduled task or Windows Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, API unhooking, and checks for sandbox environments or virtual machines by querying WMI for hardware identifiers.
Stealler was first observed in the wild in mid-2023, with a notable campaign in August 2023 targeting cryptocurrency users through fake NFT minting websites. A high-profile incident involved the compromise of over 5,000 Discord tokens in a coordinated attack using Stealler payloads distributed via compromised GitHub repositories. No specific CVEs have been directly attributed to Stealler, as it relies on social engineering rather than exploiting vulnerabilities, and no law enforcement actions have been publicly reported against its operators as of early 2025.
Known file hashes associated with Stealler include MD5: 3a7b9c8d4e2f1a6b5c0d8e9f7a6b5c4d (sample from Trellix report). Behavioral signatures include creation of scheduled tasks named "SecurityUpdateTask" and writes to registry key HKCUSoftwareMicrosoftStealler. Network IOCs include HTTPS POST requests to domains like stealer-update[.]com and user-agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Mutex names observed include "GlobalSteallerMutex2023".
The primary damage caused by Stealler is credential theft and cryptocurrency wallet compromise, leading to financial losses for affected individuals and organizations. In Q4 2023, a coordinated campaign against cryptocurrency traders resulted in an estimated $2.3 million in stolen assets. The malware predominantly targets retail investors and small-to-medium businesses in the cryptocurrency and e-commerce sectors.
Defensive measures include deploying endpoint detection and response (EDR) solutions with behavior-based rules to detect process hollowing and unauthorized scheduled task creation. Organizations should implement application control to block execution of unsigned binaries from untrusted sources, and enforce multi-factor authentication to reduce the impact of credential theft. Detailed detection rules are available in the Trellix threat advisory TR-2023-1457.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.