Skip to content

Oski

Oski Stealer is a Windows information-stealing malware family associated with credential theft and collection of other sensitive host data.

Profile source: Mallory opens in a new tab

Oski

Family profile

Oski Stealer is a Windows information-stealing malware family associated with credential theft and collection of other sensitive host data. It has been observed extracting browser credentials, cryptocurrency wallet-related data, screenshots, and system information, and it has shown behavioral overlap with closely related stealer families such as Arkei, Vidar, and possibly Mars, which can complicate precise family attribution in some cases. Reporting has noted code-sharing or lineage links between Oski and other commodity stealers in the Arkei/Vidar ecosystem.

Oski has appeared in multi-stage crimeware delivery chains alongside loaders, banking trojans, and post-exploitation tooling. Documented campaigns delivered it through phishing emails that impersonated copyright complaints and linked victims to malicious documents hosted on legitimate file-sharing services; those documents used macros to retrieve and execute follow-on payloads. Oski has also been distributed through fake coronavirus-themed landing pages reached via malicious router-based traffic redirection, as well as through cracked-software or keygen lures used to deliver stealer payloads.

On infected systems, Oski is associated with browser data theft and exfiltration of collected information in archive form. Observed artifacts linked to Oski-style activity include stolen browser history, screenshots, and host profiling data. Related stealer samples in this cluster have also downloaded browser-support libraries commonly used to access protected data from Firefox and Chromium-derived browsers. Anti-analysis behavior associated with Oski-era stealer variants includes checks for Windows Defender emulator artifacts, a technique also seen across several other commodity stealers.

Oski has circulated in underground markets, including cracked builds offered on cybercrime forums, which lowered the barrier to entry for financially motivated actors. Its use aligns with broad credential-harvesting and information-theft operations rather than narrowly targeted espionage, though campaigns delivering it have affected users across multiple countries and sectors.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration

MITRE ATT&CK

Oski in ATT&CK

20 distinct techniques

Reporting

Research mentioning Oski

Nov 2
Cyble Blog Historic

Cyble - New Laplas Clipper Distributed Via SmokeLoader

Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.

Sep 3
Talosintelligence Other

Salfram: Robbing the place without removing your name tag

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.