logo

Technical Analysis of Marco Stealer

ID: ade5c754-e045-5fbb-92c6-bc6449f1e22d

STIX ID: report--ade5c754-e045-5fbb-92c6-bc6449f1e22d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-05-01

...
...

**Executive Summary:** This technical analysis details Marco Stealer, an information-stealing malware that uses a PowerShell downloader, ARX-based string encryption, anti-analysis techniques, DLL injection and named pipes to extract browser credentials, cryptocurrency wallet data, system metadata, screenshots and other sensitive files, encrypts stolen data with AES, and exfiltrates it to hardcoded C2 endpoints (example URLs/IPs are provided).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.