Mars Stealer

First seen
2021-12-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-07-21 15:57:45
Profile updated
2026-07-07 13:47:12

Targeted industries: financial-services technology-and-telecommunications

Context

3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.

Detection coverage

  • 3 YARA rules

Detection rules

  • SEKOIA_Infostealer_Win_Mars_Stealer (yara-rule)
  • SEKOIA_Infostealer_Win_Mars_Stealer_Variant_Llcppc1 (yara-rule)
  • SEKOIA_Infostealer_Win_Mars_Stealer_Xor_Routine (yara-rule)

Related threat objects

Reports & references

  • go.recordedfuture.com — Cta 2022 0802 (report)
  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • isc.sans.edu — 28468 (report)
  • isc.sans.edu — 28468 (report)
  • ke-la.com — Information Stealers A New Landscape (report)
  • bleepingcomputer.com — New Meta Information Stealer Distributed In Malspam Campaign (report)
  • blog.malwarebytes.com — Colibri Loader Combines Task Scheduler And Powershell In Clever Persistence Technique (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mars Stealer (report)
  • esentire.com — Fake Chrome Setup Leads To Netsupportmanager Rat And Mars Stealer (report)
  • blog.sekoia.io — Mars A Red Hot Information Stealer (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Mars Stealer (report)
  • blog.cyble.com — Fake Atomic Wallet Website Distributing Mars Stealer (report)
  • x-junior.github.io — Marsstealer (report)
  • drive.google.com — View (report)
  • Microsoft — In Hot Pursuit Of Cryware Defending Hot Wallets From Attacks (report)
  • resources.infosecinstitute.com — Mars Stealer Malware Analysis (report)
  • cyberint.com — Mars Stealer (report)
  • x-junior.github.io — Marsstealer (report)
  • viuleeenz.github.io — Applied Emulation Analysis Of Marsstealer (report)
  • threatmon.io — Mars Stealer Malware Analysis Threatmon (report)
  • blog.morphisec.com — Threat Research Mars Stealer (report)
  • 3xp0rt.com — Mars Stealer (report)
  • CERT-UA — 38606 (report)
  • malwarebytes.com — Colibri Loader Combines Task Scheduler And Powershell In Clever Persistence Technique (report)
  • resources.infosecinstitute.com — Mars Stealer Malware Analysis (report)

External references