Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 2 hostnames
Exela Stealer is a Windows stealer malware family.
Profile source: Mallory opens in a new tabExela Stealer
Exela Stealer is a Windows stealer malware family. The provided content references a SnapAttack-generated attack simulation dataset for a "Windows Exela Stealer Javascript Popup" scenario in a Splunk attack_range environment, mapped to MITRE ATT&CK T1059.007. Separately, the content states that a VirusTotal Enterprise search for behavior related to ApplicationBoundEncryptionEnabled identified a few Exela Stealer samples that appear to attempt disabling Chromium application-bound encryption (ABE) via Windows registry policy. Specifically, this behavior is associated with the policy keys HKLM\Software\Policies\Google\Chrome\ApplicationBoundEncryptionEnabled and HKLM\Software\Policies\Microsoft\Edge\ApplicationBoundEncryptionEnabled; setting the value to 0 and restarting the browser disables ABE. This suggests Exela Stealer may target Chromium-based browser data such as cookies on Windows by weakening browser protections. No additional high-confidence details about Exela Stealer’s operators, infection vector, targeted industries, or broader capabilities are directly provided in the content.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 27c2134b7774f29e657f881ca9177fe6e93a9b6e03fda4579168b9099c0005a8 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.