Mars Stealer
- First seen
- 2021-12-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-21 15:57:45
- Profile updated
- 2026-07-07 13:47:12
Targeted industries: financial-services technology-and-telecommunications
Context
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.
Detection coverage
- 3 YARA rules
Detection rules
- SEKOIA_Infostealer_Win_Mars_Stealer (yara-rule)
- SEKOIA_Infostealer_Win_Mars_Stealer_Variant_Llcppc1 (yara-rule)
- SEKOIA_Infostealer_Win_Mars_Stealer_Xor_Routine (yara-rule)
Related threat objects
- Oski Stealer (malware)
Reports & references
- go.recordedfuture.com — Cta 2022 0802 (report)
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- isc.sans.edu — 28468 (report)
- isc.sans.edu — 28468 (report)
- ke-la.com — Information Stealers A New Landscape (report)
- bleepingcomputer.com — New Meta Information Stealer Distributed In Malspam Campaign (report)
- blog.malwarebytes.com — Colibri Loader Combines Task Scheduler And Powershell In Clever Persistence Technique (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mars Stealer (report)
- esentire.com — Fake Chrome Setup Leads To Netsupportmanager Rat And Mars Stealer (report)
- blog.sekoia.io — Mars A Red Hot Information Stealer (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Mars Stealer (report)
- blog.cyble.com — Fake Atomic Wallet Website Distributing Mars Stealer (report)
- x-junior.github.io — Marsstealer (report)
- drive.google.com — View (report)
- Microsoft — In Hot Pursuit Of Cryware Defending Hot Wallets From Attacks (report)
- resources.infosecinstitute.com — Mars Stealer Malware Analysis (report)
- cyberint.com — Mars Stealer (report)
- x-junior.github.io — Marsstealer (report)
- viuleeenz.github.io — Applied Emulation Analysis Of Marsstealer (report)
- threatmon.io — Mars Stealer Malware Analysis Threatmon (report)
- blog.morphisec.com — Threat Research Mars Stealer (report)
- 3xp0rt.com — Mars Stealer (report)
- CERT-UA — 38606 (report)
- malwarebytes.com — Colibri Loader Combines Task Scheduler And Powershell In Clever Persistence Technique (report)
- resources.infosecinstitute.com — Mars Stealer Malware Analysis (report)