Technical Analysis of Marco Stealer
ID: ade5c754-e045-5fbb-92c6-bc6449f1e22d
STIX ID: report--ade5c754-e045-5fbb-92c6-bc6449f1e22d
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive Summary:** This technical analysis details Marco Stealer, an information-stealing malware that uses a PowerShell downloader, ARX-based string encryption, anti-analysis techniques, DLL injection and named pipes to extract browser credentials, cryptocurrency wallet data, system metadata, screenshots and other sensitive files, encrypts stolen data with AES, and exfiltrates it to hardcoded C2 endpoints (example URLs/IPs are provided).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
