DOSTEALER

First seen
2020-05-15 00:00:00
Malware type
credential-stealer, keylogger, screen-capture
Family
Malware family
Last IoC activity
2026-07-06 12:56:49
Profile updated
2026-07-07 13:08:49

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.

Reports & references

  • socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
  • Mandiant — 17826 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dostealer (report)

External references