OmniStealer is a Python-based information stealer targeting Windows, macOS, and Linux. It harvests browser credentials, cookies, cryptocurrency wallet data and private keys, password-manager data, cloud-storage credentials, developer secrets, and source code. Its targets include Chromium-based browsers and Firefox, cryptocurrency wallet browser extensions and standalone applications, and password-manager extensions and applications. It also collects Git credentials and GitHub CLI tokens. Stolen data can be exfiltrated over HTTP, with Telegram Bot API uploads as a fallback.
OmniStealer is deployed in North Korea-linked developer-targeting operations, including the Cross-Chain TxDataHiding campaign and PolinRider supply-chain activity associated with Contagious Interview and Famous Chollima. Infection chains use fake recruitment opportunities and coding assignments, weaponized GitHub repositories, and compromised software packages. Obfuscated JavaScript loaders retrieve encrypted follow-on stages through TRON, Aptos, and BNB Smart Chain transaction data before deploying the stealer. Supporting downloaders can provision Python on Windows when needed.
The malware frequently accompanies the DEV#POPPER remote-access trojan, but serves as a separate, one-time data-harvesting payload. These operations primarily target software developers and cryptocurrency-sector personnel, seeking credentials, development assets, and material enabling access to cryptocurrency wallets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OmniStealer is a 3,500-line Python credential harvester targeting browsers, crypto wallets, password managers, and cloud storage across Windows, macOS, and Linux.
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
the first Python Downloader ( Payload1_2 (HTTP Payload Stager) ) which ultimately leads to downloading the OmniStealer malware as discussed in Part 2
The decrypted payloads then deploy remote access malware, including DEV#POPPER RAT and OmniStealer, to exfiltrate data from the compromised systems.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
“Victim receives a fake job offer via Telegram, pointing to a GitHub repo or trojanized NPM package.”
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1195.002 — Compromise Software Supply Chain (Initial Access)
“[The HTTP stager] acted as a Python dropper: it installed Python silently on the victim's machine, then used it to fetch ... the OmniStealer payload.”
“The initial loader checks transactions on TRON ... to locate encrypted JavaScript stored in BNB Smart Chain transactions.”
public/fonts/fa-solid-400.woff2 isn't a font. It's JavaScript that reads XOR-encrypted payloads from on-chain transactions
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
“A separate one-time stealer seeks browser information, password manager data, cloud storage credentials and cryptocurrency wallet material.”
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
novel tradecraft such as Cross-Chain TxDataHiding techniques combined with the subsequent creation of a takedown-proof Command and control (C2) infrastructure
a multi-layered attack leveraging novel blockchain-based command-and-control infrastructure
“C2 path /init Port 443 endpoint returning the RAT and scanner” and “C2 path /boot Port 443 Ethereum recovery endpoint.”
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a follow-on payload delivered by the PolinRider campaign. The campaign's loaders use public blockchain infrastructure to obtain encrypted follow-on payloads and conceal malicious code in configuration files, fake font files, and editor task settings. OmniStealer's specific capabilities are not detailed.
Credential and cryptocurrency-wallet stealer delivered within the XCTDH infection chain. It targets browser data, password-manager data, cloud credentials, and material from 153 cryptocurrency wallets; stolen data is exfiltrated through a messaging-bot interface.
Post links to "XCTDH Adopts Hash Hiding" and includes the hashtag #OmniStealer.
Python-based, one-shot credential harvester. It targets more than 60 wallet extensions, browser data, password managers, and cloud-storage data; the campaign's dropper silently installs Python to execute it, and it exfiltrates collected data through Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.