DeerStealer
- Malware type
- credential-stealer, botnet, rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 14:57:17
Targeted industries: financial-services technology-and-telecommunications
Context
According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system. The malware has hidden VNC capabilities for stealthy remote desktop control, collecting crypto wallets from USB sticks and over 800 browser extensions. It exfiltrates the stolen data in form of a ZIP archive to a botnet C2 server.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Deerstealer (report)
- malwarebytes.com — Threat Actor Impersonates Google Via Fake Ad For Authenticator (report)
- Broadcom/Symantec — Deerstealer Malware Spread Via Fake Google Authenticator Websites (report)
- esentire.com — Dont Get Caught In The Headlights Deerstealer Analysis (report)
- bazaar.abuse.ch — Deerstealer (report)
- cryptika.com — Deerstealer Malware Delivered Via Weaponized Lnk Using Lolbin Tools (report)