In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
Mars Stealer
Mars Stealer is a Windows information-stealing malware family that emerged in 2021 and is widely assessed as a successor to Oski Stealer within the broader Arkei-derived stealer lineage.
Profile source: Mallory opens in a new tabMars Stealer
Family profile
Mars Stealer is a Windows information-stealing malware family that emerged in 2021 and is widely assessed as a successor to Oski Stealer within the broader Arkei-derived stealer lineage. It has been sold on underground forums and has appeared in multiple criminal delivery ecosystems as a final payload, including campaigns involving Hancitor, Colibri Loader, PrivateLoader, PureCrypter, and NetSupport Manager. It has also been distributed through phishing and fake software or wallet-themed download sites, including cryptocurrency lures impersonating Atomic Wallet, as well as cracked software, keygens, and cloned software pages.
Mars Stealer is designed to harvest sensitive data from infected Windows systems, with particular emphasis on browser-stored information and cryptocurrency-related assets. Reported targeting includes browser credentials, cookies, autofill data, browsing history, downloads, saved payment data, Discord data, screenshots, certificates, RDP credentials, browser extensions, cryptocurrency wallet extensions, desktop wallet data, and 2FA-related plugins or application data. It has been described as part of the broader "cryware" trend because of its focus on locating installed wallets, collecting wallet-related files, bundling the stolen material, and exfiltrating it to attacker-controlled infrastructure over HTTP POST.
Technical reporting indicates that Mars Stealer retrieves legitimate DLL dependencies from command-and-control infrastructure, with newer samples downloading them as a single ZIP archive rather than as separate files. Stolen data is likewise packaged into ZIP archives and sent via HTTP POST. Some analyses also describe grabber and loader functionality, enabling collection of files from selected user directories and delivery of additional payloads. In observed intrusions, Mars Stealer has been deployed through obfuscated script chains and injected into legitimate processes as part of defense-evasion tradecraft.
Documented anti-analysis and evasion features include anti-debugging, anti-sandbox timing checks, anti-emulation checks associated with Windows Defender emulation artifacts, mutex-based reinfection avoidance, self-deletion, and process injection. One reported intrusion showed the malware using a custom-loaded copy of NTDLL to inject into explorer.exe in an apparent attempt to reduce visibility from security tooling. Mars Stealer has also been linked to language-based execution filtering that avoids running on systems configured for several CIS-region languages.
Mars Stealer has been observed in financially motivated campaigns targeting general users and cryptocurrency holders rather than a single vertical. Its recurring use in loader ecosystems and wallet-themed phishing operations, combined with its credential- and wallet-theft focus, has made it a notable infostealer in the post-Raccoon period despite not reaching the same market prominence as some competing stealer families.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Post Exploitation
- Process Injection
- Session Hijacking
Reported operators
Threat actors
2 named in public reportingMalware advertised in underground forums as Mars Stealer started to appear in 2021.
MITRE ATT&CK
Mars Stealer in ATT&CK
27 distinct techniquesTechniques
27 techniquesReporting
Research mentioning Mars Stealer
EternityTeam: A New Prominent Threat Group
EternityTeam has emerged as a prominent malware seller on Russian-speaking underground forums and Telegram, marketing a modular malware-as-a-service toolkit that includes an infostealer, worm, miner, clipper, botnet/dropper, and ransomware. Researchers said the group has been active since at least 2022 and has paired aggressive advertising with customer support, release notes, and builder-style customization that lets buyers assemble malware binaries from separately sold components, lowering the barrier to entry for less-skilled attackers. The group's flagship offering, Eternity Stealer, is a .NET infostealer sold on subscription that targets browser data, cryptocurrency wallet information, application credentials, and Growtopia accounts. Observed samples masqueraded as Growtopia-related tools, exfiltrating stolen data over HTTPS to EternityTeam-controlled servers before forwarding it to operators through a Telegram bot. Researchers also reported samples in the wild and noted that parts of the stealer may reuse code from earlier public or criminal projects, but assessed the broader Eternity ecosystem as a credible and scalable threat because of its active distribution, modular design, and ransomware-capable tooling.
Vidar (Malware Family)
Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.