Malware advertised in underground forums as Mars Stealer started to appear in 2021.
Mars Stealer
Mars Stealer is an information-stealing malware family first observed in 2021 and sold on underground forums, including Russian-speaking forums, as a successor to Oski Stealer and part of the Arkei-derived stealer lineage alongside Vidar and Oski.
Profile source: Mallory opens in a new tabMars Stealer
Family profile
Mars Stealer is an information-stealing malware family first observed in 2021 and sold on underground forums, including Russian-speaking forums, as a successor to Oski Stealer and part of the Arkei-derived stealer lineage alongside Vidar and Oski. It has been described as targeting Windows systems and stealing browser data, stored credentials, cookies, autofill data, password-manager data, Discord data, downloads, browsing history, screenshots, certificates, RDP credentials, and cryptocurrency-related data including browser extensions, crypto extensions, web wallets, desktop wallets, wallet files, and 2FA plugins/extensions. Reported capabilities include loader and grabber functionality, self-deletion, anti-debugging, anti-sandboxing, anti-emulation checks, language-based execution avoidance, and mutex-based reinfection avoidance. In one analyzed sample, Mars Stealer loaded a renamed copy of NTDLL.DLL and injected itself into explorer.exe to help evade EDR monitoring.
Observed delivery vectors in the provided content include Hancitor follow-on infections, a Colibri Loader campaign initiated via a malicious Word document using remote template injection and PowerShell/BITS to fetch the loader, phishing via a fake Atomic Wallet website that delivered a ZIP containing a malicious batch file, and a fake ChromeSetup ISO hosted on a malicious domain that installed NetSupportManager RAT before deploying Mars Stealer through obfuscated AutoIt scripts. The Atomic Wallet campaign used PowerShell, Base64 decoding, AES decryption, and GZip decompression, then downloaded Mars Stealer from a Discord server into %LOCALAPPDATA%. The Colibri campaign ultimately delivered a Mars Stealer payload after establishing persistence. Mars Stealer has also been associated with cryptocurrency-focused theft activity and is cited by Microsoft as an example of "cryware."
Behavior noted in the content includes retrieval of legitimate DLL dependencies; unlike Vidar and Oski, current Mars Stealer samples retrieved required DLLs as a single ZIP archive. Exfiltration was described as HTTP POST of ZIP archives containing stolen data to command-and-control servers. Specific infrastructure and indicators directly mentioned include a March 2022 sample with SHA-256 7022a16d455a3ad78d0bbeeb2793cb35e48822c3a0a8d9eaa326ffc91dd9e625 using sughicent[.]com and 5.63.155[.]126:80; a fake Atomic Wallet campaign using atomic-wallet[.]net, bit[.]ly/3PRDyH8, batch file SHA-256 33d0d9fe89f0dba2b89347a0e2e6deb22542476d98676187f8c1eb529cb3997f, and Mars Stealer executable SHA-256 10afe233525aaf99064e4e444f11a8fc01f8b9f508e4f123fd76b314a6d360f9; a Colibri-delivered Mars payload install.exe with SHA-256 b92f4b4684951ff2e5abdb1280e6bff80a14b83f25e4f3de39985f188d0f3aad; and an intrusion using googleglstatupdt[.]com/LEND/ChromeSetup[.]iso, AutoIt scripts una.wmd, fervore.wmd, and vai.wmd, RC4 key 344868553478223918282826525, and mutex 67820366929896267194. CERT-UA also lists MARSSTEALER among tools used by UAC-0050, but the provided content does not attribute Mars Stealer exclusively to that actor.
Reported operators
Threat actors
2 named in public reporting…SECTOPRAT, MARSSTEALER, DARKTRACKRAT…
MITRE ATT&CK
Mars Stealer in ATT&CK
27 distinct techniquesTechniques
27 techniquesReporting
Research mentioning Mars Stealer
Llama AI Stealer or Lumma Stealer | by Ireneusz Tarnowski | Medium
Lumma most likely comes from Mars Stealer.
Applied Emulation - Analysis of MarsStealer :: Security Undisguised
dp = Dumpulator ( "mars_stealer.dump" , quiet = True )
Cyble - Fake Atomic Wallet Website Distributing Mars Stealer
Cyble analyzes a fake Atomic Wallet website that is being used to distribute Mars Stealer to cryptocurrency users... After a detailed investigation, the downloaded file was identified as a Mars Stealer sample. Mars Stealer was discovered in June 2021 and was available for sale on a few underground cybercrime forums.
eSentire Threat Intelligence Malware Analysis: Mars Stealer | eSentire
Mars Stealer is an information-stealing malware that first appeared on hacking forums in June 2021, a year after its predecessor Oski Stealer was discontinued in June 2020.
In hot pursuit of ‘cryware’: Defending hot wallets from attacks | Microsoft Security Blog
The increasing popularity of cryptocurrency has also led to the emergence of cryware like Mars Stealer and RedLine Stealer. These threats aim to steal cryptocurrencies through wallet data theft, clipboard manipulation, phishing and scams, or even misleading smart contracts.
New Meta information stealer distributed in malspam campaign
META is one of the novel info-stealers, along with Mars Stealer and BlackGuard, whose operators wish to take advantage of Raccoon Stealer's exit from the market...
Colibri Loader combines Task Scheduler and PowerShell in clever persistence technique - ThreatDown by Malwarebytes
Our Threat Intelligence Team recently uncovered a new Colibri Loader campaign delivering the Mars Stealer as final payload.
Arkei Variants: From Vidar to Mars Stealer - SANS ISC
Malware advertised in underground forums as Mars Stealer started to appear in 2021.