TerraStealer
Aliases: SONE, StealerOne, Taurus Loader Stealer Module
- First seen
- 2021-07-01 00:00:00
- Malware type
- credential-stealer, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 12:40:46
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email clients, web browsers, and file transfer utilities. Attributed to Golden Chickens.
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- ESET — More Evil Deep Look Evilnum Toolset (report)
- github.com — Evilnum (report)
- quointelligence.eu — Golden Chickens Evolution Of The Maas (report)
- recordedfuture.com — Terrastealerv2 And Terralogger (report)
- medium.com — The Chicken Keeps Laying New Eggs Uncovering New Gc Maas Tools Used By Top Tier Threat Actors 531D80A6B4E9 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Terra Stealer (report)
- go.recordedfuture.com — Cta 2025 0501 (report)
- twitter.com — 1275746149719252992 (report)