VoltStealer

Stealer

⚠️ Overview

VoltStealer is a credential-stealing malware first documented in July 2023 by the cybersecurity firm Zscaler, classified as an information stealer (infostealer) developed by an unknown threat actor. It targets web browsers, email clients, and cryptocurrency wallets, primarily operating against English-speaking users.

🔧 Technical Capabilities

VoltStealer employs a multi-stage attack chain: initial infection occurs via phishing emails containing malicious Microsoft Office documents or downloader scripts (VBS, PowerShell). Once executed, the dropper downloads a .NET-based payload that extracts passwords, cookies, auto-fill data, and credit card information from Chromium-based browsers (Chrome, Edge, Brave) and Mozilla Firefox. It targets email clients such as Outlook and Thunderbird, and scans for cryptocurrency wallet extensions (e.g., MetaMask, Coinbase Wallet). The malware uses HTTP POST requests over encrypted (HTTPS) channels to exfiltrate stolen data to a command-and-control (C2) server. Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, VoltStealer checks for sandbox environments by verifying low system memory (< 2GB) or the presence of analysis tools like Wireshark; if detected, it terminates. It also uses obfuscation of strings via Base64 encoding and XOR cipher to hinder static analysis. According to Zscaler's analysis, the malware does not self-propagate but relies on social engineering.

📜 History & Notable Incidents

Zscaler’s ThreatLabz first reported VoltStealer in a July 2023 blog post, describing campaigns targeting European and North American users via tax-themed phishing lures. No high-profile victims or specific CVEs have been publicly attributed to VoltStealer; the malware does not exploit system vulnerabilities but uses user interaction. No law enforcement actions have been reported as of early 2025. MITRE ATT&CK techniques observed include T1059.001 (PowerShell), T1047 (WMI), and T1005 (Data from Local System).

🔍 Detection Indicators

Known file hashes for VoltStealer samples include SHA-256: 7a4c1e2f3b... (Zscaler’s advisory lists partial hashes). Behavioral indicators: creation of scheduled tasks named ‘VoltUpdate’ or ‘WindowsEventCheck’; network traffic to random subdomains under `.xyz` or `.top` TLDs with User-Agent strings mimicking `Mozilla/5.0 (Windows NT 10.0; Win64; x64)`. Registry keys at HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnceVolt are used for persistence. Mutex names such as `VoltStealerMutex` have been observed in sandbox reports.

☠️ Risk & Impact

Primary damage is data exfiltration of login credentials, financial information, and cryptocurrency wallet keys, leading to identity theft and financial loss. Based on Zscaler’s telemetry, the most affected sectors include finance, e-commerce, and cryptocurrency exchanges. Exfiltrated data is often sold on dark web markets or used for account takeover fraud.

🛡️ Mitigation

Organizations should enforce email filtering policies to block malicious attachments with VBS and PowerShell scripts. Enable Windows Defender Antivirus with cloud-delivered protection and use custom YARA rules from Zscaler’s threat advisory to detect VoltStealer payloads. Multi-factor authentication can mitigate credential theft damage.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.