FickerStealer
FickerStealer is a Rust-based malware-as-a-service infostealer that emerged in 2020 and is traded in Russian-language cybercrime ecosystems.
Profile source: Mallory opens in a new tabFickerStealer
Family profile
FickerStealer is a Rust-based malware-as-a-service infostealer that emerged in 2020 and is traded in Russian-language cybercrime ecosystems. It is designed to harvest sensitive data from infected Windows systems, including saved passwords, browser autocomplete data, and cryptocurrency wallet information. FickerStealer has been observed as a final-stage payload in multistage crimeware operations and is commonly delivered by other malware or exploit-driven infection chains rather than acting as a standalone initial access tool.
Observed delivery chains include Hancitor infections distributed through malicious spam and macro-enabled Microsoft Office documents, where the loader retrieves additional payloads such as FickerStealer after execution on the victim host. It has also been delivered through web-based exploitation, including Rig exploit kit activity that redirected victims from lure websites to exploit landing pages targeting vulnerable browsers and plugins before downloading the stealer. Separate multistage infrastructure associated with the Netbounce cluster has also delivered FickerStealer alongside other stealers such as Vidar.
FickerStealer primarily serves credential and financial-data theft objectives in cybercrime campaigns. Its use as a MaaS offering and its appearance across multiple unrelated delivery ecosystems indicate that it is an opportunistic commodity payload favored for post-compromise monetization on Windows endpoints.
Capabilities
- Credential Theft
- Crypto Theft
- Post Exploitation
MITRE ATT&CK