Skip to content

FickerStealer

FickerStealer is a Rust-based malware-as-a-service infostealer that emerged in 2020 and is traded in Russian-language cybercrime ecosystems.

Profile source: Mallory opens in a new tab

FickerStealer

Family profile

FickerStealer is a Rust-based malware-as-a-service infostealer that emerged in 2020 and is traded in Russian-language cybercrime ecosystems. It is designed to harvest sensitive data from infected Windows systems, including saved passwords, browser autocomplete data, and cryptocurrency wallet information. FickerStealer has been observed as a final-stage payload in multistage crimeware operations and is commonly delivered by other malware or exploit-driven infection chains rather than acting as a standalone initial access tool.

Observed delivery chains include Hancitor infections distributed through malicious spam and macro-enabled Microsoft Office documents, where the loader retrieves additional payloads such as FickerStealer after execution on the victim host. It has also been delivered through web-based exploitation, including Rig exploit kit activity that redirected victims from lure websites to exploit landing pages targeting vulnerable browsers and plugins before downloading the stealer. Separate multistage infrastructure associated with the Netbounce cluster has also delivered FickerStealer alongside other stealers such as Vidar.

FickerStealer primarily serves credential and financial-data theft objectives in cybercrime campaigns. Its use as a MaaS offering and its appearance across multiple unrelated delivery ecosystems indicate that it is an opportunistic commodity payload favored for post-compromise monetization on Windows endpoints.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Post Exploitation

MITRE ATT&CK

FickerStealer in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.