Arkei Stealer

Aliases: ArkeiStealer

First seen
2018-05-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-07-22 02:38:46
Profile updated
2026-07-07 14:06:33

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

Arkei is a stealer that appeared around May 2018. It collects data about browsers (saved passwords and autofill forms), cryptocurrency wallets, and steal files matching an attacker-defined pattern. It then exfiltrates everything in a zip file uploaded to the attacker's panel. Later, it was forked and used as a base to create Vidar stealer.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Vidar (yara-rule)

Reports & references

  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Arkei Stealer (report)
  • blog.minerva-labs.com — A Long List Of Arkei Stealers Browser Crypto Wallets (report)
  • drive.google.com — View (report)
  • m4lcode.github.io — Vidar (report)
  • fumik0.com — Lets Dig Into Vidar An Arkei Copycat Forked Stealer In Depth Analysis (report)
  • bleepingcomputer.com — Hacker Breaches Syscoin Github Account And Poisons Official Client (report)
  • isc.sans.edu — 28468 (report)
  • isc.sans.edu — 28468 (report)
  • ke-la.com — Information Stealers A New Landscape (report)
  • threatmon.io — Arkei Stealer Analysis Threatmon (report)
  • forensicitguy.github.io — Analyzing Stealer Msi Using Msitools (report)
  • blogs.blackberry.com — Threat Thursday Arkei Infostealer (report)

External references