Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Sep 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 18 IP / 9 hostnames
DeerStealer is a Windows-focused malware-as-a-service infostealer, also marketed in some contexts as XFiles or XFiles Spyware.
Profile source: Mallory opens in a new tabDeerStealer
DeerStealer is a Windows-focused malware-as-a-service infostealer, also marketed in some contexts as XFiles or XFiles Spyware. It is sold through tiered subscriptions and has been observed in multiple criminal delivery ecosystems, including fake software installers, fake browser or application updates, malvertising, GitHub-hosted lures, signed MSI packages, and ClickFix-style social-engineering chains that trick users into manually launching malicious commands. It has also appeared as a final payload delivered by loaders such as HijackLoader and in campaigns associated with actors including TA2727, while other reporting links its broader delivery ecosystem to operators such as TAG-150/GrayBravo.
Its core function is theft of high-value user data. DeerStealer targets credentials, cookies, autofill data, payment card data, browsing artifacts, and session material from a large set of web browsers. It also targets numerous browser extensions, especially cryptocurrency wallets, password managers, authenticators, and related security tools. Beyond browsers, it has been reported stealing data from desktop cryptocurrency wallets, messaging applications, VPN clients, FTP clients, remote desktop and VNC software, gaming platforms, and email clients. Some observed variants or service tiers also include clipboard hijacking for cryptocurrency theft, hidden VNC for live remote surveillance, and keylogging.
The malware commonly fingerprints infected hosts and exfiltrates collected data to attacker-controlled infrastructure, often using encrypted archives over HTTPS. Reporting also describes heavy obfuscation, per-build variation, string decryption mechanisms, and in-memory execution techniques intended to hinder analysis and evade detection. DeerStealer has been delivered through DLL sideloading and loader chains that abuse legitimate signed binaries, as well as through trojanized installers that establish persistence before deploying the stealer. Observed persistence mechanisms include scheduled tasks and user-run startup entries.
DeerStealer is part of the contemporary commodity stealer ecosystem and is used in financially motivated operations focused on credential theft, session theft, cryptocurrency theft, and downstream account compromise. Its recurring use in fake update, fake utility, and installer-based campaigns makes it relevant to both enterprise and consumer environments, particularly where users are exposed to malvertising, phishing-style lures, or untrusted software downloads.
C2 tracking
Derp observations, rolling seven-day window
Samples
052f0caff530a67f9a17df5795806d9b01a551f309e434cd4eb92fba8e024051 28e985edba59127261da83fe963b0a3674d9007840acd8db505fec6ac455c987 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac baa739eba49601b21067818ff725e168894a0c186e90405180687cb26970f89a 265ff3e568105a01f8c6d52912715be58f550096b12332fdc86c7c4e80746323 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 3a297d846199ddff323b30eadb510daedbbd08a9e76949c06df09e1592dd0f02 7584a1b0daf329afd2123a71dadb54abb9fe353838b33cc2469506859145f588 c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 Reported operators
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
A WiX Burn installer calling itself "Antonomasia" by "Cyme" bundles a fully functional copy of Active@ Password Changer alongside DeerStealer -- a MaaS infostealer that will drain your browser credentials, crypto wallets, and messaging sessions before you finish clicking through the setup wizard.
MITRE ATT&CK
Reporting
Researchers reported that threat actor TA2726 used a malicious traffic-distribution framework on 1,509 compromised WordPress sites to turn them into malware delivery gateways. The operation relied on injected fake-plugin JavaScript, admin-ajax bootstrapping, and same-origin REST or query endpoints to profile visitors and selectively redirect them based on geography and device type. Eligible Windows users were funneled into TA569’s SocGholish fake browser update chain, which led to GhoLoader execution, while the broader ecosystem has also routed victims to other payloads including Lumma Stealer, DeerStealer, Marcher, and the macOS stealer FrigidStealer. Proofpoint previously identified TA2726 as a malicious traffic distribution service working alongside other actors, including TA2727, in web inject campaigns that abuse compromised websites and fake browser update lures across Windows, Android, and macOS. In the newer WordPress-focused activity, the observed s6qgn implant remained active from April through July 2026 even after disruption efforts against parts of the SocGholish ecosystem, and some infected sites were later repurposed for a separate ClickFix injection using Polygon EtherHiding smart-contract lookups. The findings indicate a resilient and increasingly collaborative fake-update ecosystem in which shared infrastructure and compromised websites are reused to deliver multiple malware families and complicate attribution.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.