New Oski Stealer Variant, "Mars Stealer", Targets Credentials, Crypto, and 2FA
ID: 62944ed2-f7c2-5794-8452-db8abd6f334f
STIX ID: report--62944ed2-f7c2-5794-8452-db8abd6f334f
Feed Name: WatchGuard Secplicity Blog
Mars Stealer (a revived Oski Stealer variant) is an information-stealing malware sold as MaaS that exfiltrates browser data, credentials, cryptocurrency wallet addresses/seeds and 2FA tokens. It employs Base64/RC4 string obfuscation, run-time DLL decryption/loading, anti-analysis and anti-emulation checks, runtime DLL downloads from C2 (e.g., cookreceipts.fun), a custom loader/grabber for file transfer/execution, and self-removal to evade detection; historically related distribution included router DNS hijacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
