Mars Stealer is a Windows information-stealing malware family that emerged in 2021 and is widely assessed as a successor to Oski Stealer within the broader Arkei-derived stealer lineage. It has been sold on underground forums and has appeared in multiple criminal delivery ecosystems as a final payload, including campaigns involving Hancitor, Colibri Loader, PrivateLoader, PureCrypter, and NetSupport Manager. It has also been distributed through phishing and fake software or wallet-themed download sites, including cryptocurrency lures impersonating Atomic Wallet, as well as cracked software, keygens, and cloned software pages.
Mars Stealer is designed to harvest sensitive data from infected Windows systems, with particular emphasis on browser-stored information and cryptocurrency-related assets. Reported targeting includes browser credentials, cookies, autofill data, browsing history, downloads, saved payment data, Discord data, screenshots, certificates, RDP credentials, browser extensions, cryptocurrency wallet extensions, desktop wallet data, and 2FA-related plugins or application data. It has been described as part of the broader "cryware" trend because of its focus on locating installed wallets, collecting wallet-related files, bundling the stolen material, and exfiltrating it to attacker-controlled infrastructure over HTTP POST.
Technical reporting indicates that Mars Stealer retrieves legitimate DLL dependencies from command-and-control infrastructure, with newer samples downloading them as a single ZIP archive rather than as separate files. Stolen data is likewise packaged into ZIP archives and sent via HTTP POST. Some analyses also describe grabber and loader functionality, enabling collection of files from selected user directories and delivery of additional payloads. In observed intrusions, Mars Stealer has been deployed through obfuscated script chains and injected into legitimate processes as part of defense-evasion tradecraft.
Documented anti-analysis and evasion features include anti-debugging, anti-sandbox timing checks, anti-emulation checks associated with Windows Defender emulation artifacts, mutex-based reinfection avoidance, self-deletion, and process injection. One reported intrusion showed the malware using a custom-loaded copy of NTDLL to inject into explorer.exe in an apparent attempt to reduce visibility from security tooling. Mars Stealer has also been linked to language-based execution filtering that avoids running on systems configured for several CIS-region languages.
Mars Stealer has been observed in financially motivated campaigns targeting general users and cryptocurrency holders rather than a single vertical. Its recurring use in loader ecosystems and wallet-themed phishing operations, combined with its credential- and wallet-theft focus, has made it a notable infostealer in the post-Raccoon period despite not reaching the same market prominence as some competing stealer families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
Malware advertised in underground forums as Mars Stealer started to appear in 2021.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
aNpRAHx.exe (original name: 3uAirPlayer.exe) was used to plant the following AutoIt scripts... The AutoIt scripts were highly obfuscated.
Then, the .bat file executes PowerShell content using AtomicWallet_Setup.bat.exe, which further decodes the base64-encoded content and decrypts it using an AES algorithm that stores a Gzip Compressed stream in the memory.
The NetSupportManager RAT was obfuscated by the attacker as ‘21m_18_033.exe’... another executable was dropped via the remote session on the victim’s machine – consoleappmrss.exe.
NTDLL.DLL is responsible for injecting Mars Stealer into explorer.exe module during the runtime.
Mars Stealer can self-delete itself after successfully exfiltrating the victim’s data... The self-delete command is executed via command line: /c timeout /t 5 & del /f /q "%s" & exit
For anti-sandboxing, the stealer sleeps for 16000 milliseconds and calls GetTickCount API... If the value is less than 12000, it means that the Sleep function was skipped by the debugger or sandbox, and the sample exits.
The .bat file then copies powershell.exe into the current directory , renames it as AtomicWallet_Setup.bat.exe, and then hides it using the attrib command.
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Credential Access ... T1528 ... Steal Application Access Token
MITRE ATT&CK® Techniques Tactic Technique ID Technique Name ... Credential Access ... T1539 ... Steal Web Session Cookies
Conclusion According to our research, the TAs behind Mars stealer are adopting sophisticated phishing attacks to distribute Mars Stealer and gather user credentials, system information, and other sensitive data.
In this scenario, an attacker traverses the target user’s filesystem, determines which wallet apps are installed, and then exfiltrates a predefined list of wallet files.
For anti-sandboxing, the stealer sleeps for 16000 milliseconds and calls GetTickCount API... If the value is less than 12000, it means that the Sleep function was skipped by the debugger or sandbox, and the sample exits.
a simple but effective way to steal hot wallet data is to target the wallet application’s storage files... then exfiltrates a predefined list of wallet files.
The name of the file which the PrivateLoader bot used to exfiltrate data was ‘NOP8QIMGV3W47Y.zip’... Saving the hex data using a ‘.zip’ extension and extracting the contents, a file directory consisting of system information and Chrome and Edge browsers’ Autofill data in cleartext .txt file format could be seen.
The infected machine occasionally sends the POST requests to http://162.33.178[.]122/fakeurl.htm, which is a NetSupportManager server... The victim then reaches out to the Mars Stealer C2 server (/request)
Mars Stealer then bundles the stolen data and exfiltrates it to an attacker-controlled command-and-control (C2) server via HTTP POST.
After users’ devices were redirected to pages instructing them to download a password-protected archive, they subsequently contacted cdn.discordapp[.]com over SSL. The archive files which users downloaded over these SSL connections likely contained the PrivateLoader loader module.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of another information stealer in related prior investigations.
An infostealer delivered as a follow-on payload by PrivateLoader; one case showed exfiltration of browser autofill and system information consistent with Mars Stealer activity.
Referenced as the likely predecessor or origin family for Lumma Stealer.
The content references a memory dump named "mars_stealer.dump" and a deobfuscation routine, indicating analysis of the Mars Stealer malware and its obfuscated strings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.