Oski Stealer is a Windows information-stealing malware family associated with credential theft and collection of other sensitive host data. It has been observed extracting browser credentials, cryptocurrency wallet-related data, screenshots, and system information, and it has shown behavioral overlap with closely related stealer families such as Arkei, Vidar, and possibly Mars, which can complicate precise family attribution in some cases. Reporting has noted code-sharing or lineage links between Oski and other commodity stealers in the Arkei/Vidar ecosystem.
Oski has appeared in multi-stage crimeware delivery chains alongside loaders, banking trojans, and post-exploitation tooling. Documented campaigns delivered it through phishing emails that impersonated copyright complaints and linked victims to malicious documents hosted on legitimate file-sharing services; those documents used macros to retrieve and execute follow-on payloads. Oski has also been distributed through fake coronavirus-themed landing pages reached via malicious router-based traffic redirection, as well as through cracked-software or keygen lures used to deliver stealer payloads.
On infected systems, Oski is associated with browser data theft and exfiltration of collected information in archive form. Observed artifacts linked to Oski-style activity include stolen browser history, screenshots, and host profiling data. Related stealer samples in this cluster have also downloaded browser-support libraries commonly used to access protected data from Firefox and Chromium-derived browsers. Anti-analysis behavior associated with Oski-era stealer variants includes checks for Windows Defender emulator artifacts, a technique also seen across several other commodity stealers.
Oski has circulated in underground markets, including cracked builds offered on cybercrime forums, which lowered the barrier to entry for financially motivated actors. Its use aligns with broad credential-harvesting and information-theft operations rather than narrowly targeted espionage, though campaigns delivering it have affected users across multiple countries and sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious-sites users land on claim to offer an app that provides “the latest information and instructions about coronavirus (COVID-19).” Users who click on the download button are ultimately redirected to one of several Bitbucket pages that offers a file that installs malware.
Cisco Talos recently uncovered a series of email campaigns utilizing links to malicious documents hosted on legitimate file-sharing platforms to spread malware.
The crypter used in these campaigns is undergoing active development and improvements to obfuscate the contents of malware payloads.
the initial malware payloads used the same crypter, which obfuscates the malicious contents present in the binary executable and make analysis more difficult.
Threat hunters often focus on spotting command-and-control (C2) servers, open directories typically identified by the phrase “Index of” and phishing components.
Users who click on the download button are ultimately redirected to one of several Bitbucket pages that offers a file that installs malware.
779 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer used for credential theft; a cracked version was offered on RAMP.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
Stealer mentioned as using Windows Defender emulator artifact checks (HAL9TH/JohnDoe) for anti-emulation.
Referenced as the predecessor or possible earlier version related to Mars.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.