Skip to content
Malware family

Exela Stealer

Exela Stealer is a Windows stealer malware family.

Profile source: Mallory opens in a new tab

Exela Stealer

Family profile

Exela Stealer is a Windows stealer malware family. The provided content references a SnapAttack-generated attack simulation dataset for a "Windows Exela Stealer Javascript Popup" scenario in a Splunk attack_range environment, mapped to MITRE ATT&CK T1059.007. Separately, the content states that a VirusTotal Enterprise search for behavior related to ApplicationBoundEncryptionEnabled identified a few Exela Stealer samples that appear to attempt disabling Chromium application-bound encryption (ABE) via Windows registry policy. Specifically, this behavior is associated with the policy keys HKLM\Software\Policies\Google\Chrome\ApplicationBoundEncryptionEnabled and HKLM\Software\Policies\Microsoft\Edge\ApplicationBoundEncryptionEnabled; setting the value to 0 and restarting the browser disables ABE. This suggests Exela Stealer may target Chromium-based browser data such as cookies on Windows by weakening browser protections. No additional high-confidence details about Exela Stealerโ€™s operators, infection vector, targeted industries, or broader capabilities are directly provided in the content.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
8 IP / 6 hostnames

Leading locations

  • CN3
  • NL3
  • US3
  • CA1
  • DE1
  • HK1
  • IE1
  • KR1

Leading providers

  • Amazon.com, Inc.3
  • Omegatech LTD2
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch1
  • Cloudflare, Inc.1
  • CTG Server Limited1
  • FEMO IT SOLUTIONS LIMITED1

Infrastructure traits

  • Hosting 13
  • Anycast 1
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

Exela Stealer in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.