Arkei Stealer
Aliases: ArkeiStealer
- First seen
- 2018-05-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:38:46
- Profile updated
- 2026-07-07 14:06:33
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Arkei is a stealer that appeared around May 2018. It collects data about browsers (saved passwords and autofill forms), cryptocurrency wallets, and steal files matching an attacker-defined pattern. It then exfiltrates everything in a zip file uploaded to the attacker's panel. Later, it was forked and used as a base to create Vidar stealer.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Vidar (yara-rule)
Reports & references
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Arkei Stealer (report)
- blog.minerva-labs.com — A Long List Of Arkei Stealers Browser Crypto Wallets (report)
- drive.google.com — View (report)
- m4lcode.github.io — Vidar (report)
- fumik0.com — Lets Dig Into Vidar An Arkei Copycat Forked Stealer In Depth Analysis (report)
- bleepingcomputer.com — Hacker Breaches Syscoin Github Account And Poisons Official Client (report)
- isc.sans.edu — 28468 (report)
- isc.sans.edu — 28468 (report)
- ke-la.com — Information Stealers A New Landscape (report)
- threatmon.io — Arkei Stealer Analysis Threatmon (report)
- forensicitguy.github.io — Analyzing Stealer Msi Using Msitools (report)
- blogs.blackberry.com — Threat Thursday Arkei Infostealer (report)