Ficker Stealer

First seen
2021-01-01 00:00:00
Malware type
credential-stealer, downloader, spyware
Family
Malware family
Last IoC activity
2026-07-15 05:01:46
Profile updated
2026-07-07 13:44:03

Targeted industries: financial-services technology-and-telecommunications

Context

According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information, cryptocurrency wallets and browser information from applications such as WinSCP, Discord, Google Chrome, Electrum, etc. It does all that by implementing a different approach than other stealers (we’ll cover it later). Additionally, FickerStealer can function as a File Grabber and collect additional files from the compromised machine, and it can act as a Downloader to download and execute several second-stage malware.

Reports & references

  • blogs.blackberry.com — Kraken The Code On Prometheus (report)
  • threatresearch.ext.hp.com — Hp Bromium Threat Insights Report Q4 2020 (report)
  • medium.com — Gcleaner Garbage Provider Since 2019 2708E7C87A8A (report)
  • binarydefense.com — Analysis Of Hancitor When Boring Begets Beacon (report)
  • spamhaus.com — Botnet Update Q1 2021 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Fickerstealer (report)
  • bleepingcomputer.com — Fake Microsoft Store Spotify Sites Spread Info Stealing Malware (report)
  • cyberark.com — Fickerstealer A New Rust Player In The Market (report)
  • twitter.com — 1321209656774135810 (report)
  • blogs.blackberry.com — Threat Thursday Ficker Infostealer Malware (report)

External references