Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 1 hostnames
DeerStealer is a Windows-focused information stealer sold as a malware-as-a-service platform.
Profile source: Mallory opens in a new tabDeerStealer
DeerStealer is a Windows-focused information stealer sold as a malware-as-a-service platform. Reporting in the provided content describes subscription tiers ranging from $200/month to $3,000/month, with higher tiers adding hidden VNC, keylogging, clipper functionality, SmartScreen bypass, and remote process management. It is characterized as a credential-focused stealer and has been observed targeting browser passwords, cookies, session tokens, autofill and credit-card data, browsing history, cryptocurrency wallets, browser extensions, Discord and Telegram tokens, messaging-session data, FTP and VPN credentials, Office documents, and OneDrive contents. Multiple reports state it targets data from more than 50 browsers, more than 800 browser extensions, and numerous desktop and hardware-wallet-related applications.
The malware has been delivered through several infection chains in the source material. Observed vectors include fake browser update lures and web inject chains, malicious MSI installers built with WiX Toolset 4.0.0.0, EV-signed MSI packages that abuse trust and SmartScreen reputation, HTA/mshta-based MaaS affiliate builds, ClickFix-style phishing pages that trick users into manually executing PowerShell, and trojanized software bundles or bootstrapper installers. Specific execution chains include DLL sideloading via legitimate signed binaries such as iMyFone Feedback Utils.exe with a trojanized Qt5Network.dll, Zoner Photo Studio VoTransmitt.exe with a trojanized sciter32.dll, and installers that unpack intermediate loaders before deploying DeerStealer. One analyzed sample used a GhostPulse loader that concealed the payload in headerless PNG-style IDAT chunks stored in cachedrv.xml, with encrypted configuration in servicetable68.cfg. Another WiX Burn sample disguised as "Antonomasia" by publisher "Cyme" used Bichromate.dll masquerading as Adobe CCMNative.dll to decrypt and execute DeerStealer entirely in memory while displaying a legitimate Active@ Password Changer decoy.
Persistence mechanisms directly mentioned in the content include scheduled tasks, HKCU Run key persistence using the value name AppVTemplate, and persistence established by MSI CustomActions before final payload deployment. Anti-analysis and evasion features described in the content include use of signed or EV-signed binaries and installers, in-memory decryption and execution, DLL sideloading, encrypted configuration and payload containers, self-deletion in HTA-based variants, anti-sandbox checks, and rootkit-like or stealth-oriented capabilities. One report states DeerStealer uses Telegram for execution notifications, and another states stolen data may be staged locally in SQLite tables named ribs_collection and ribs_payload before exfiltration via XOR-encrypted HTTPS POST requests and AES-encrypted ZIP archives through a Cloudflare-backed proxy layer.
Associated threat activity in the content links DeerStealer to multiple financially motivated ecosystems and operators. Proofpoint reported TA2727 delivering DeerStealer to Windows users via fake browser update chains, with TA2726 acting as a traffic distribution service redirecting victims by geography. TAG-150, later named GrayBravo, is reported to have used CastleLoader infrastructure to deliver DeerStealer among other payloads. DeerStealer also appears in ShadowLadder campaign reporting, in ITarian abuse chains following fake browser update lures, and in affiliate-operated MaaS activity including HTA-based builds and Telegram-advertised sales. One report attributes the DeerStealer MaaS ecosystem to sales by @LuciferXfiles on Telegram-based cybercrime forums.
High-confidence indicators and artifacts explicitly mentioned in the content include: MSI RVJVAUQL.msi SHA-256 ee5e941218bcf1285b2640c4b2f8baf3ffa44a73b6894ce871a22cbc24b80600; trojanized Qt5Network.dll SHA-256 73d2b832d07ab4f6f893f915ca35a43359250c659900357642c6af1f9cd5e130; cachedrv.xml SHA-256 fdbc169b439b430b7c4688ec3bc56de604d1eaaed66a7c919225981a654ad2ae; servicetable68.cfg SHA-256 3d8f0ef413fec6f85e335ca089da1f67439dbe1c8f5c01fc001b5c03b58028bd; WiX Burn sample SHA-256 04bb4867d35e77e8e391f3829cf07a542a73815fc8be975a7733790d6e04243c; Bichromate.dll SHA-256 58a6b1fe90145f8ae431d05952d1751e705ae46a81be1c2257f5e1e0ce0292c7; encrypted payload file jri SHA-256 d704f5f01487ca3340454240868515de1a43a1b65e5b4a97a74ab409c8441f82; config file yodpxub SHA-256 1a5991a30e9d339cbb0143d4bd134509cf4effc7fead7f4f7dcc059990efd669; active or associated C2 domains telluricaphelion[.]com, loadinnnhr[.]today, nacreousoculus[.]pro, ncloud-servers[.]shop, watchlist-verizon[.]com, 365-drive[.]com; campaign domains statswpmy[.]com and trackingmyadsas[.]com; and ClickFix-delivered MSI SHA-256 ead6b1f0add059261ac56e9453131184bc0ae2869f983b6a41a1abb167edf151 with precursor batch file cv.bat SHA-256 2b74674587a65cfc9c2c47865ca8128b4f7e47142bd4f53ed6f3cb5cf37f7a6b.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30955adfb864533f1d6a46b25f02aa79c5c5891d0b536eb9da9d33bcaa1061db 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7fe76ccceaec33d07e90e96ac144be83ed622c8af8b134d7429020e476cf4716 b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49 b7a06c7dd0943016ee68b5c14ec8a20578df56f9d9fa5f6ea73df6daa5211c07 f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd Reported operators
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
A WiX Burn installer calling itself "Antonomasia" by "Cyme" bundles a fully functional copy of Active@ Password Changer alongside DeerStealer -- a MaaS infostealer that will drain your browser credentials, crypto wallets, and messaging sessions before you finish clicking through the setup wizard.
MITRE ATT&CK
Reporting
Researchers reported that threat actor TA2726 used a malicious traffic-distribution framework on 1,509 compromised WordPress sites to turn them into malware delivery gateways. The operation relied on injected fake-plugin JavaScript, admin-ajax bootstrapping, and same-origin REST or query endpoints to profile visitors and selectively redirect them based on geography and device type. Eligible Windows users were funneled into TA569’s SocGholish fake browser update chain, which led to GhoLoader execution, while the broader ecosystem has also routed victims to other payloads including Lumma Stealer, DeerStealer, Marcher, and the macOS stealer FrigidStealer. Proofpoint previously identified TA2726 as a malicious traffic distribution service working alongside other actors, including TA2727, in web inject campaigns that abuse compromised websites and fake browser update lures across Windows, Android, and macOS. In the newer WordPress-focused activity, the observed s6qgn implant remained active from April through July 2026 even after disruption efforts against parts of the SocGholish ecosystem, and some infected sites were later repurposed for a separate ClickFix injection using Polygon EtherHiding smart-contract lookups. The findings indicate a resilient and increasingly collaborative fake-update ecosystem in which shared infrastructure and compromised websites are reused to deliver multiple malware families and complicate attribution.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.