Oski Stealer

First seen
2019-11-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-07-22 00:34:13
Profile updated
2026-07-07 14:42:56

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums. It collects different types of data (cryptocurrency wallets, saved passwords, files matching an attacker-defined pattern etc) and it exfiltrates it in a zip file uploaded to the attacker's panel.

Related threat objects

Reports & references

  • yoroi.company — The Wayback Campaign A Large Scale Operation Hiding In Plain Sight (report)
  • blog.minerva-labs.com — Underminer Exploit Kit The More You Check The More Evasive You Become (report)
  • isc.sans.edu — 28468 (report)
  • cyberint.com — Mars Stealer (report)
  • 3xp0rt.com — Mars Stealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Oski (report)
  • medium.com — Oski Stealer A Credential Theft Malware B9Bba5164601 (report)
  • labs.bitdefender.com — New Router Dns Hijacking Attacks Abuse Bitbucket To Host Infostealer (report)
  • drive.google.com — View (report)
  • twitter.com — 1160874557454131200 (report)
  • cyberark.com — Meet Oski Stealer An In Depth Analysis Of The Popular Credential Stealer (report)
  • drive.google.com — View (report)
  • bitdefender.com — Labs (report)
  • yoroi.company — The Wayback Campaign A Large Scale Operation Hiding In Plain Sight (report)
  • rapid7.com — Unified Mdr Xdr Vm (report)

External references