Ficker Stealer
According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information, cryptocurrency wallets and browser information from applications such as WinSCP, Discord, Google Chrome, Electrum, etc. It does all that by implementing a different approach than other stealers (we’ll cover it later). Additionally, FickerStealer can function as a File Grabber and collect additional files from the compromised machine, and it can act as a Downloader to download and execute several second-stage malware.
C2 Infrastructure
Last 7 days
| Date | C2 Hosts |
|---|---|
| Mar 24, 2026 | 1 |
Further Reading
Explore expert insights on secure communications from BlackBerry — covering government, critical infrastructure, resilience, compliance, and trusted communications at scale.
Explore expert insights on secure communications from BlackBerry — covering government, critical infrastructure, resilience, compliance, and trusted communications at scale.
Attackers are promoting sites impersonating the Microsoft Store, Spotify, and an online document converter that distribute malware to steal credit cards and passwords saved in web browsers.
This blog introduces a new information stealer, written in Rust and interestingly named FickerStealer. In this blog post, we provide an in-depth analysis of this new threat and its obfuscation...