Skip to content

Exela Stealer

Exela Stealer is a Windows stealer malware family.

Profile source: Mallory opens in a new tab

Exela Stealer

Family profile

Exela Stealer is a Windows stealer malware family. The provided content references a SnapAttack-generated attack simulation dataset for a "Windows Exela Stealer Javascript Popup" scenario in a Splunk attack_range environment, mapped to MITRE ATT&CK T1059.007. Separately, the content states that a VirusTotal Enterprise search for behavior related to ApplicationBoundEncryptionEnabled identified a few Exela Stealer samples that appear to attempt disabling Chromium application-bound encryption (ABE) via Windows registry policy. Specifically, this behavior is associated with the policy keys HKLM\Software\Policies\Google\Chrome\ApplicationBoundEncryptionEnabled and HKLM\Software\Policies\Microsoft\Edge\ApplicationBoundEncryptionEnabled; setting the value to 0 and restarting the browser disables ABE. This suggests Exela Stealer may target Chromium-based browser data such as cookies on Windows by weakening browser protections. No additional high-confidence details about Exela Stealer’s operators, infection vector, targeted industries, or broader capabilities are directly provided in the content.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Sep 5, 2026
Feed role
C2 / Distribution
Host form
1 IP / 2 hostnames

Leading locations

  • US2
  • NL1

Leading providers

  • Amazon.com, Inc.1
  • Google LLC1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

MITRE ATT&CK

Exela Stealer in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.