DeerStealer

Malware type
credential-stealer, botnet, rat
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 14:57:17

Targeted industries: financial-services technology-and-telecommunications

Context

According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system. The malware has hidden VNC capabilities for stealthy remote desktop control, collecting crypto wallets from USB sticks and over 800 browser extensions. It exfiltrates the stolen data in form of a ZIP archive to a botnet C2 server.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Deerstealer (report)
  • malwarebytes.com — Threat Actor Impersonates Google Via Fake Ad For Authenticator (report)
  • Broadcom/Symantec — Deerstealer Malware Spread Via Fake Google Authenticator Websites (report)
  • esentire.com — Dont Get Caught In The Headlights Deerstealer Analysis (report)
  • bazaar.abuse.ch — Deerstealer (report)
  • cryptika.com — Deerstealer Malware Delivered Via Weaponized Lnk Using Lolbin Tools (report)

External references