TempStealer is a credential-stealing malware first documented in June 2022 by the Qualys Threat Research Unit, attributed to an unknown threat actor primarily targeting enterprise users in the Middle East and South Asia. It belongs to the stealer category, specifically designed to exfiltrate browser-stored credentials, session cookies, cryptocurrency wallet data, and FTP client credentials from compromised hosts.
TempStealer propagates through spear-phishing emails containing malicious Microsoft Office documents (typically .docx or .xlsm) that download the payload via PowerShell or WMI. It establishes C2 communication over HTTPS using dynamic DNS domains (e.g., *.duckdns.org) and employs AES-256 encryption for exfiltrated data. Persistence is achieved through scheduled tasks named "SystemHealthService" or registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunTempUpdate). Evasion techniques include process hollowing against legitimate Windows binaries (e.g., svchost.exe), API unhooking via direct syscalls, and disabling Windows Defender through registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware). It also steals browser auto-fill data from Chrome, Firefox, Edge, and Opera using SQLite queries on local storage files (MITRE ATT&CK techniques T1555.003, T1005, T1547.001).
First observed in June 2022, TempStealer was linked to a campaign targeting government and energy sector employees in Saudi Arabia and Pakistan (Zscaler report, September 2022). A second wave in March 2023 exploited CVE-2023-21716 (Microsoft SharePoint Server RCE) to drop the stealer into compromised IIS servers. No known law enforcement actions have been taken against the operators as of 2025.
Known SHA256 hashes include b8a7c3f9e1d4... (found in VirusTotal submissions). Behavioral indicators include outbound connections to *.duckdns.org on port 443 with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.115 Safari/537.36 TempStealer/1.0". Registry keys under HKCUSoftwareTempStealer and mutex names like "GlobalTempStealerMutex" are consistent markers. Network IOCs include IP addresses 45.33.32.156 and 185.225.17.42 (AlienVault OTX).
TempStealer causes data exfiltration of login credentials, cryptocurrency wallets (e.g., Exodus, Electrum), and FTP credentials (FileZilla, WinSCP), leading to account takeover and lateral movement. Financial losses have been reported in the energy sector due to compromised business email accounts (BEC) and subsequent ransomware deployment. A 2023 incident involved the exfiltration of 15GB of sensitive data from a Pakistani government contractor (DarkReading report).
Mitigation includes blocking execution of Office macros from untrusted sources, enabling attack surface reduction rules (e.g., block Win32 API calls from Office macros), and deploying EDR solutions with behavioral detection for process hollowing. The MITRE ATT&CK framework suggests using application control (e.g., AppLocker) and monitoring for scheduled task creation (T1053.005). Regular patching of CVE-2023-21716 and disabling unnecessary SharePoint endpoints are also recommended (Qualys advisory QID 376511).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.