logo

New Oski Stealer Variant, "Mars Stealer", Targets Credentials, Crypto, and 2FA

ID: 62944ed2-f7c2-5794-8452-db8abd6f334f

STIX ID: report--62944ed2-f7c2-5794-8452-db8abd6f334f

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2022-02-08

Date Updated: 2026-05-01

Author: The Editor

...
...

Mars Stealer (a revived Oski Stealer variant) is an information-stealing malware sold as MaaS that exfiltrates browser data, credentials, cryptocurrency wallet addresses/seeds and 2FA tokens. It employs Base64/RC4 string obfuscation, run-time DLL decryption/loading, anti-analysis and anti-emulation checks, runtime DLL downloads from C2 (e.g., cookreceipts.fun), a custom loader/grabber for file transfer/execution, and self-removal to evade detection; historically related distribution included router DNS hijacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.