Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 6 hostnames
Exela Stealer is a Windows stealer malware family.
Profile source: Mallory opens in a new tabExela Stealer
Exela Stealer is a Windows stealer malware family. The provided content references a SnapAttack-generated attack simulation dataset for a "Windows Exela Stealer Javascript Popup" scenario in a Splunk attack_range environment, mapped to MITRE ATT&CK T1059.007. Separately, the content states that a VirusTotal Enterprise search for behavior related to ApplicationBoundEncryptionEnabled identified a few Exela Stealer samples that appear to attempt disabling Chromium application-bound encryption (ABE) via Windows registry policy. Specifically, this behavior is associated with the policy keys HKLM\Software\Policies\Google\Chrome\ApplicationBoundEncryptionEnabled and HKLM\Software\Policies\Microsoft\Edge\ApplicationBoundEncryptionEnabled; setting the value to 0 and restarting the browser disables ABE. This suggests Exela Stealer may target Chromium-based browser data such as cookies on Windows by weakening browser protections. No additional high-confidence details about Exela Stealerโs operators, infection vector, targeted industries, or broader capabilities are directly provided in the content.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 27c2134b7774f29e657f881ca9177fe6e93a9b6e03fda4579168b9099c0005a8 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09 ecda70414eaa3354ef877c71c445d49294f142fc694e81f0002d385ff1060d02 1ebf64ceb8ec5601ead8cd44c4a3b22a7e9b5a8a4432ea70e96e2837495b19a9 526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.