Skip to content

DeerStealer

DeerStealer is a Windows-focused malware-as-a-service infostealer, also marketed in some contexts as XFiles or XFiles Spyware.

Profile source: Mallory opens in a new tab

DeerStealer

Family profile

DeerStealer is a Windows-focused malware-as-a-service infostealer, also marketed in some contexts as XFiles or XFiles Spyware. It is sold through tiered subscriptions and has been observed in multiple criminal delivery ecosystems, including fake software installers, fake browser or application updates, malvertising, GitHub-hosted lures, signed MSI packages, and ClickFix-style social-engineering chains that trick users into manually launching malicious commands. It has also appeared as a final payload delivered by loaders such as HijackLoader and in campaigns associated with actors including TA2727, while other reporting links its broader delivery ecosystem to operators such as TAG-150/GrayBravo.

Its core function is theft of high-value user data. DeerStealer targets credentials, cookies, autofill data, payment card data, browsing artifacts, and session material from a large set of web browsers. It also targets numerous browser extensions, especially cryptocurrency wallets, password managers, authenticators, and related security tools. Beyond browsers, it has been reported stealing data from desktop cryptocurrency wallets, messaging applications, VPN clients, FTP clients, remote desktop and VNC software, gaming platforms, and email clients. Some observed variants or service tiers also include clipboard hijacking for cryptocurrency theft, hidden VNC for live remote surveillance, and keylogging.

The malware commonly fingerprints infected hosts and exfiltrates collected data to attacker-controlled infrastructure, often using encrypted archives over HTTPS. Reporting also describes heavy obfuscation, per-build variation, string decryption mechanisms, and in-memory execution techniques intended to hinder analysis and evade detection. DeerStealer has been delivered through DLL sideloading and loader chains that abuse legitimate signed binaries, as well as through trojanized installers that establish persistence before deploying the stealer. Observed persistence mechanisms include scheduled tasks and user-run startup entries.

DeerStealer is part of the contemporary commodity stealer ecosystem and is used in financially motivated operations focused on credential theft, session theft, cryptocurrency theft, and downstream account compromise. Its recurring use in fake update, fake utility, and installer-based campaigns makes it relevant to both enterprise and consumer environments, particularly where users are exposed to malvertising, phishing-style lures, or untrusted software downloads.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Sep 7, 2026
Feed role
C2 / Distribution
Host form
18 IP / 9 hostnames

Leading locations

  • DE7
  • US5
  • CN4
  • NL3
  • HK2
  • CY1
  • ES1
  • GB1
  • IN1
  • JP1
  • SI1

Leading providers

  • FEMO IT SOLUTIONS LIMITED5
  • CHINA UNICOM China169 Backbone2
  • Cloudflare, Inc.2
  • Omegatech LTD2
  • ANS ACADEMY LIMITED1
  • Bharti Airtel Ltd., Telemedia Services1

Infrastructure traits

  • Hosting 23
  • Anycast 3

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA2727

Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.

@LuciferXfiles

A WiX Burn installer calling itself "Antonomasia" by "Cyme" bundles a fully functional copy of Active@ Password Changer alongside DeerStealer -- a MaaS infostealer that will drain your browser credentials, crypto wallets, and messaging sessions before you finish clicking through the setup wizard.

MITRE ATT&CK

DeerStealer in ATT&CK

42 distinct techniques

Reporting

Research mentioning DeerStealer

Jul 21
Derp Ca

TA2726 turns 1,509 WordPress sites into malware launchpads | Derp

Researchers reported that threat actor TA2726 used a malicious traffic-distribution framework on 1,509 compromised WordPress sites to turn them into malware delivery gateways. The operation relied on injected fake-plugin JavaScript, admin-ajax bootstrapping, and same-origin REST or query endpoints to profile visitors and selectively redirect them based on geography and device type. Eligible Windows users were funneled into TA569’s SocGholish fake browser update chain, which led to GhoLoader execution, while the broader ecosystem has also routed victims to other payloads including Lumma Stealer, DeerStealer, Marcher, and the macOS stealer FrigidStealer. Proofpoint previously identified TA2726 as a malicious traffic distribution service working alongside other actors, including TA2727, in web inject campaigns that abuse compromised websites and fake browser update lures across Windows, Android, and macOS. In the newer WordPress-focused activity, the observed s6qgn implant remained active from April through July 2026 even after disruption efforts against parts of the SocGholish ecosystem, and some infected sites were later repurposed for a separate ClickFix injection using Polygon EtherHiding smart-contract lookups. The findings indicate a resilient and increasingly collaborative fake-update ecosystem in which shared infrastructure and compromised websites are reused to deliver multiple malware families and complicate attribution.

Feb 14
Proofpoint

An Update on Fake Updates: Two New Actors, and New Mac Malware | Proofpoint US

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.