Mars is a Windows information-stealing malware family that emerged in 2021 and has been marketed in cybercriminal communities as a low-cost, beginner-friendly stealer. It is primarily designed to harvest credentials, cryptocurrency wallet data, wallet-related two-factor authentication plugins, and basic host profiling information from infected systems. Reporting has also described Mars as capable of downloading and executing additional payloads from operator-controlled infrastructure, giving it limited follow-on delivery functionality beyond pure data theft.
Mars has been advertised across numerous underground forums, Telegram channels, and darknet marketplaces, including sales activity under the “MarsTeam” branding. It has been positioned by sellers as a successor or improvement over Oski, and multiple analyses note technical or ecosystem overlap among Mars, Arkei, Vidar, Oski, and later stealer families such as Lumma and StealC. Those overlaps suggest code reuse, shared developer knowledge, or common lineage within the Russian-speaking infostealer ecosystem, although exact lineage is not always attributable with high confidence.
The malware targets Windows hosts and is associated with theft of browser- and wallet-related data, including credentials and cryptocurrency assets. Mars has also been cited among information stealers used in ransomware intrusion chains, where stolen credentials and financial data can support later-stage compromise. In addition, separate reporting on SolarMarker uses the name “Mars” for a distinct backdoor module within that malware framework; that module is not the same malware family as the standalone Mars infostealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, the script sets up persistence measures by creating a startup task that copies the final PowerShell command and re-runs the execution of the Mars DLL.
Like the previous stager, the Mars module also remotely receives execution commands by dropping new files onto the victim system and spawning processes to run them, or through direct PowerShell text commands.
Finally, the script sets up persistence measures by creating a startup task that copies the final PowerShell command and re-runs the execution of the Mars DLL.
The stager also possesses the ability to remotely receive execution commands by dropping new PS1 or PE files onto the victim system at "\AppData\Local\Temp\" directory with a filename of 24 randomly generated alphanumeric characters and executing them either through PowerShell or process hollowing
This program is executed in tandem with the rest of Solarmarker's initialization to act as misdirection for the victim by attempting to look like a legitimate document.
The stager also possesses the ability to remotely receive execution commands by dropping new PS1 or PE files onto the victim system at "\AppData\Local\Temp\" directory with a filename of 24 randomly generated alphanumeric characters and executing them either through PowerShell or process hollowing
Stealers commonly capture system configuration data within a text file... let’s start with system.txt.
The actor now uses a 16 byte, randomly generated AES symmetric key to encrypt the data sent to and from the C2 host... This key is sent with the victim identification string back to the actor's C2 in the first HTTP request, which is itself encrypted using an RSA asymmetric key pair.
92 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer used in ransomware attacks.
SolarMarker backdoor module that launches on startup and delivers additional payloads such as the VNC client.
Named information-stealing malware listed as detectable via favicon hash hunting of exposed infrastructure.
Stealer mentioned as using Windows Defender emulator artifact checks (HAL9TH/JohnDoe) for anti-emulation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.