DeerStealer is a Windows-focused malware-as-a-service infostealer, also marketed in some contexts as XFiles or XFiles Spyware. It is sold through tiered subscriptions and has been observed in multiple criminal delivery ecosystems, including fake software installers, fake browser or application updates, malvertising, GitHub-hosted lures, signed MSI packages, and ClickFix-style social-engineering chains that trick users into manually launching malicious commands. It has also appeared as a final payload delivered by loaders such as HijackLoader and in campaigns associated with actors including TA2727, while other reporting links its broader delivery ecosystem to operators such as TAG-150/GrayBravo.
Its core function is theft of high-value user data. DeerStealer targets credentials, cookies, autofill data, payment card data, browsing artifacts, and session material from a large set of web browsers. It also targets numerous browser extensions, especially cryptocurrency wallets, password managers, authenticators, and related security tools. Beyond browsers, it has been reported stealing data from desktop cryptocurrency wallets, messaging applications, VPN clients, FTP clients, remote desktop and VNC software, gaming platforms, and email clients. Some observed variants or service tiers also include clipboard hijacking for cryptocurrency theft, hidden VNC for live remote surveillance, and keylogging.
The malware commonly fingerprints infected hosts and exfiltrates collected data to attacker-controlled infrastructure, often using encrypted archives over HTTPS. Reporting also describes heavy obfuscation, per-build variation, string decryption mechanisms, and in-memory execution techniques intended to hinder analysis and evade detection. DeerStealer has been delivered through DLL sideloading and loader chains that abuse legitimate signed binaries, as well as through trojanized installers that establish persistence before deploying the stealer. Observed persistence mechanisms include scheduled tasks and user-run startup entries.
DeerStealer is part of the contemporary commodity stealer ecosystem and is used in financially motivated operations focused on credential theft, session theft, cryptocurrency theft, and downstream account compromise. Its recurring use in fake update, fake utility, and installer-based campaigns makes it relevant to both enterprise and consumer environments, particularly where users are exposed to malvertising, phishing-style lures, or untrusted software downloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
A WiX Burn installer calling itself "Antonomasia" by "Cyme" bundles a fully functional copy of Active@ Password Changer alongside DeerStealer -- a MaaS infostealer that will drain your browser credentials, crypto wallets, and messaging sessions before you finish clicking through the setup wizard.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
We see a number of redirects via intermediary domains controlled by the attacker, before landing on a fake site for Authenticator. Fake site leads to signed payload hosted on Github
T1053.005 Persistence Scheduled Task/Job: Scheduled Task zceWriter, dyApp, Pluginsecurity_dbg
The purpose of the next stage is to module stomp the legitimate binary input.dll with core HijackLoader shellcode . The inject process (legitimate signed Q-Dir renamed as SecureLoader_test.exe) is then started in a suspended state, the HijackLoader configuration is decrypted/parsed from Kleanmean.py , and the DeerStealer payload is written to a new section in the inject process.
DeerStealer employs a significant amount of obfuscation, in order to hinder the analysis process and evade antivirus signatures.
the whole premise of these attacks relies on social engineering... some unknown individual was able to impersonate Google and successfully push malware disguised as a branded Google product
T1036.005 Defense Evasion Masquerading: Match Legitimate Name "Antonomasia" by "Cyme" + Active@ Password Changer decoy
The purpose of the next stage is to module stomp the legitimate binary input.dll with core HijackLoader shellcode . The inject process (legitimate signed Q-Dir renamed as SecureLoader_test.exe) is then started in a suspended state, the HijackLoader configuration is decrypted/parsed from Kleanmean.py , and the DeerStealer payload is written to a new section in the inject process.
The inject process (legitimate signed Q-Dir renamed as SecureLoader_test.exe) is then started in a suspended state
the purpose of this stage is to resolve APIs and read/decrypt the next stage.
stored cookies, passwords, autofill, and credit cards are harvested. Cookies from Chromium based browsers are retrieved from memory following successful communications with the C2 server.
including the InstallDate, InstallTime, machine GUID from the registry keys below
The initial request to the C2 proxy contains several identifiers to fingerprint the victim machine, including the InstallDate, InstallTime... and the machine’s processor name.
Through the file grabber module, threat actors can retrieve files from victim machines by specifying rules, or in other words, paths and file extensions to exfiltrate.
T1074.001 Collection Data Staged: Local Data Staging SQLite databases (ribs_collection, ribs_payload)
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer distributed by copycat actors using similar fake-update JavaScript lures.
An infostealer delivered as a secondary payload following ITarian abuse. It is used to steal information after persistence and DLL sideloading activity.
A secondary payload delivered by CastleLoader.
DeerStealer is a malware-as-a-service infostealer delivered here via a malicious WiX Burn installer. It decrypts and executes in memory, steals credentials from 50+ browsers, targets 14+ crypto wallets and 800+ browser extensions, captures messaging sessions, runs a hidden VNC server, logs keystrokes, establishes persistence via a Run key and scheduled tasks, and exfiltrates stolen data over encrypted HTTPS channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.