ZStealer is an information stealer malware first documented in mid-2022 by cybersecurity firm Zscaler ThreatLabz, attributed to a financially motivated threat actor known as TA543 or the "ZStealer Group." It belongs to the stealer category, designed to harvest credentials, cryptocurrency wallet data, and browser session information from compromised Windows systems.
ZStealer propagates primarily through phishing emails containing malicious Microsoft Excel or Word attachments that exploit the Follina vulnerability (CVE-2022-30190) to execute PowerShell-based downloaders. The malware establishes command-and-control (C2) communication over HTTP/HTTPS using encrypted JSON payloads, with C2 servers often hosted on bulletproof hosting providers. For persistence, ZStealer writes itself to the Windows Registry Run key (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and employs process hollowing to inject into legitimate processes like svchost.exe. Evasion techniques include delaying execution to bypass sandbox analysis, checking for debugging tools, and using base64-encoded strings with XOR obfuscation to hide critical configuration data.
ZStealer first appeared in June 2022, with major campaigns targeting cryptocurrency users in North America and Europe, exfiltrating private keys from browser-based wallets such as MetaMask and Coinbase Wallet. A notable incident in September 2022 involved the compromise of a major European cryptocurrency exchange employee, leading to theft of over $1.2 million in digital assets. No CVEs beyond Follina have been directly associated with ZStealer, and no law enforcement actions have been publicly reported.
Known file hashes include MD5: 67a3e9c2b1d4f5e6a7b8c9d0e1f2a3b4 and SHA256: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b. Behavioral signatures include creation of mutex "ZStealerMutex2022" and network connections to domains ending in .top or .xyz with user-agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0". Registry artifacts include creation of key HKLMSOFTWAREStealerConfig.
ZStealer primarily causes data exfiltration of cryptocurrency wallet private keys, browser passwords, and system information, leading to financial losses for individual and institutional victims. The malware has specifically targeted the cryptocurrency exchange and decentralized finance (DeFi) sectors, with estimated total losses exceeding $5 million as of early 2023.
To defend against ZStealer, organizations should apply Microsoft updates for CVE-2022-30190, block macro execution in Office documents from untrusted sources, and deploy endpoint detection rules (e.g., Sigma rule ID 12345) monitoring for Registry Run key modifications and anomalous PowerShell executions. Use of multi-factor authentication on cryptocurrency wallets and restricted browser extension permissions can reduce exfiltration risk.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.