Echelon
Aliases: Echelon-Stealer
- First seen
- 2021-05-15 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-10 00:11:46
- Profile updated
- 2026-07-07 14:59:29
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ru
Context
Echelon is a credential-stealer malware family known to target financial and technology sectors, stealing sensitive information such as passwords and authentication tokens. It has been observed in the wild since 2021, with operations largely focused on the United States and Russia.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Echelon (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Echelon (report)
- safeguardcyber.com — Echelon Malware Crypto Wallet Stealer Malware (report)