DOSTEALER
- First seen
- 2020-05-15 00:00:00
- Malware type
- credential-stealer, keylogger, screen-capture
- Family
- Malware family
- Last IoC activity
- 2026-07-06 12:56:49
- Profile updated
- 2026-07-07 13:08:49
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.
Reports & references
- socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
- Mandiant — 17826 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dostealer (report)