Skip to content

Oski

Oski is an information-stealing malware family used for credential theft.

Profile source: Mallory opens in a new tab

Oski

Family profile

Oski is an information-stealing malware family used for credential theft. Reported capabilities include extracting browser credentials, cryptocurrency wallet addresses, and other sensitive information from infected systems. It has also been referenced in relation to Windows Defender emulator evasion research, where Oski was among stealer families observed using simple anti-emulation checks between 2018 and 2022. One cited technique involved checking emulator artifacts such as the computer name HAL9TH, username JohnDoe, or the file path C:\INTERNAL\__empty.

Observed delivery included a campaign that abused compromised or exposed routers to redirect users attempting to visit legitimate domains to fake coronavirus-themed sites. Those sites redirected victims to Bitbucket pages hosting an Oski installer. In that activity, malicious DNS lookups were served from 109.234.35.230 and 94.103.82.249, and at least four Bitbucket accounts were used. Bitdefender observed the campaign beginning around March 18 and peaking on March 23, with Germany, France, and the United States among the most-targeted locations.

Oski is also referenced as a predecessor to Mars Stealer, with some claims suggesting Mars is a new version of Oski and later reporting describing Mars as an improved successor. Separately, leaked/cracked listings for OSKI Stealer appeared on the Russian-language cybercrime forum RAMP, indicating criminal-market availability.

MITRE ATT&CK

Oski in ATT&CK

4 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.