Evrial is a Windows information-stealing Trojan with cryptocurrency clipboard-hijacking capabilities, sold on Russian-language criminal forums and distributed in the wild. Buyers receive a payload builder and a web-based management panel for configuring replacement strings and reviewing stolen data and clipboard activity.
Evrial steals browser cookies and stored credentials from browsers including Chrome, Yandex, Orbitum, Opera, Amigo, Torch, and Comodo, as well as credentials from Pidgin and FileZilla. It also collects Bitcoin wallet files and desktop documents, captures the active window, and packages stolen information into ZIP archives for upload to an attacker-controlled server.
The malware monitors the Windows clipboard for Bitcoin, Litecoin, Monero, WebMoney, and Qiwi payment strings and Steam trade links. When it detects a supported string, it uploads the original value to a remote server, retrieves an attacker-configured replacement, and substitutes that replacement into the clipboard. This allows attackers to redirect cryptocurrency payments and Steam item trades when victims paste the modified contents.
Evrial has been distributed both as a standalone payload and as an embedded component of Supreme miner. Samples have been linked to operations using the actor alias scat01. The malware author known as TheBottle publicly claimed authorship of Evrial.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the individual claimed responsibility for creating several malware families, including Odysseus Project, Evrial, Ovidiy Stealer, and several others.
This sample is a non-obfuscated Evrial stealer. When we check its configuration, we see the following “Owner” field... “scat01”.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
By digging further among Super Info posts, we found an announcement about game accounts sales (Steam, WoT, Origin). Here we should note that stealers observed above are capable of stealing passwords from different games and game distribution platforms.
Evrial will also steal bitcoin wallets, stored passwords, documents from the victim's desktop, and a screenshot of the active windows.
In addition to monitoring and modifying the clipboard, Evrial will also steal bitcoin wallets, stored passwords, documents from the victim's desktop, and a screenshot of the active windows.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Non-obfuscated stealer whose configuration contains the owner field 'scat01'; also embedded inside Supreme miner samples distributed from gameshack[.]ru.
Referenced for comparison because of similar collection targets and ZIP-based exfiltration. The article explicitly states that there is no proof linking the analyzed stealer's author to these other cases.
Named by the confessed author as one of several malware families he created and released.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.