Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 6 hostnames
Exela Stealer is a Windows stealer malware family.
Profile source: Mallory opens in a new tabExela Stealer
Exela Stealer is a Windows stealer malware family. The provided content references a SnapAttack-generated attack simulation dataset for a "Windows Exela Stealer Javascript Popup" scenario in a Splunk attack_range environment, mapped to MITRE ATT&CK T1059.007. Separately, the content states that a VirusTotal Enterprise search for behavior related to ApplicationBoundEncryptionEnabled identified a few Exela Stealer samples that appear to attempt disabling Chromium application-bound encryption (ABE) via Windows registry policy. Specifically, this behavior is associated with the policy keys HKLM\Software\Policies\Google\Chrome\ApplicationBoundEncryptionEnabled and HKLM\Software\Policies\Microsoft\Edge\ApplicationBoundEncryptionEnabled; setting the value to 0 and restarting the browser disables ABE. This suggests Exela Stealer may target Chromium-based browser data such as cookies on Windows by weakening browser protections. No additional high-confidence details about Exela Stealerโs operators, infection vector, targeted industries, or broader capabilities are directly provided in the content.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 1ebf64ceb8ec5601ead8cd44c4a3b22a7e9b5a8a4432ea70e96e2837495b19a9 2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 7f68c7a7d5d2eadbb20f564cb6835e55c017ce6f140d2caeefaa38fe38b47e0c 27c2134b7774f29e657f881ca9177fe6e93a9b6e03fda4579168b9099c0005a8 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 ecda70414eaa3354ef877c71c445d49294f142fc694e81f0002d385ff1060d02 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.