BLACK FRIDAY: 2-for-1 offer NOVEMBER 20 - 26 See details
43
Global rank
75 infographic chevron month
Month rank
77 infographic chevron week
Week rank
0
IOCs

Arkei is a stealer type malware capable of collecting passwords, autosaved forms, cryptocurrency wallet credentials, and files.

Stealer
Type
ex-USSR
Origin
21 May, 2018
First seen
17 October, 2024
Last seen
Also known as
ArkeiStealer

How to analyze Arkei with ANY.RUN

Type
ex-USSR
Origin
21 May, 2018
First seen
17 October, 2024
Last seen

IOCs

IP addresses
5.252.178.50
104.0.0.0
103.0.0.0
45.84.0.112
45.67.229.135
45.67.35.117
176.126.113.228
146.19.247.187
62.204.41.126
Hashes
b5f582b49d200b8fcb116877761d58fcfc5781db1c07981d5c0ad457dc4ff8de
b2035278317fdde246d44e0c5a2b0fd339b6d4fac4fe70ce4a42c874e8da8085
0908f5d74f3c765b6b5fd40832bc75f7148d50ad45404b001bcc119c5046ce23
b6f40dd082b44319fbd7842304913172f6056bd3df5bcb059777c281ffa092bd
5ea2cd6bbb850ae2fa90f87743d9ea896a7a7060b78db5932838000e8c6ddb0f
a59c57c65a4949bf1c9fd39f269cbdcfe500ea6842133dab9a2a4a979a7733d0
0613fb423686c8270532aead0d9eeec5473d2902f12da71507f60dfa98892615
5fdf4c4eb4dae826de4677abbe76c63ec9c8aa5e7a192aa4eab15b29920df6be
88182016daa697b08bb26ef40195a3c9271f42479cfa4be5e0824386de459e27
efeff2fc675585f7665b4011edfcb7b8823e2294eaefa09743b8596989d58fbb
537c3e56e01ced9e64abbe83dd28f0a74a8ad634e46de55b62556fd5006be206
4c4e0fa35a2a634ad8c070f7ffe6f79f62ac9d12af74231797b68ece3e2cf1a1
6f9f9b04ee68fd5afc48fd73184c329a8d351ca715e917210f379beb90d707c5
864dfa53d603b9271b225ec43b0b82aa5dfdbd3a856549e8c51cfaf2ecbb197b
c9fa109bdedb71ce9967b8dfbbc3386a62756f16aab226849f071f1d692ffac1
c7d3374ba81f3ffcb2261c8a93df8b354c0d3d244b0dbecfb3eef5f7c07c444c
ea8665c41c6bf69b83fa4817a8099b723c324a177dacc0fe5f2cd7ee0ca69c36
70a64683435a354ea333b201cbdcc6462f484020cf2d74d1c1e09ef9f21af79d
c819bff14d4cff52015cde3b51d09c43515d6cadb4db674ed45cd26d43b1b5b1
8c54ba3429e3f5a65b6b31b84bcfc6d2b4b91cc385e50a5e656f92278603a421
Domains
mas.to
URLs
http://ip-api.com/line/
http://l3monrat.com/server.php
http://l3monrat.com/www//7.jpg
http://l3monrat.com/www//5.jpg
http://l3monrat.com/www//4.jpg
http://l3monrat.com/www//3.jpg
http://l3monrat.com/www//2.jpg
http://l3monrat.com/www//1.jpg
http://l3monrat.com/www//6.jpg
http://kenesrakishev.net/wp-admin/admin-ajax.php
https://t.me/tatlimark
https://steamcommunity.com/profiles/76561199536605936
http://104.194.151.11/AP.php
https://t.me/litlebey
https://steamcommunity.com/profiles/76561199472399815
http://62.204.41.69/
http://sughicent.com/
https://koyu.space/@ronxik123
http://prepepe.ac.ug/nss3.dll
http://prepepe.ac.ug/sqlite3.dll
Last Seen at
Last Seen at

Recent blog posts

post image
Malware Analysis Report in One Click
watchers 7289
comments 0
post image
Cyber Information Gathering: Techniques and T...
watchers 451
comments 0
post image
ANY.RUN’s Upgraded Linux Sandbox for Fast and...
watchers 572
comments 0

What is Arkei malware

Arkei is a stealer designed to exfiltrate information from infected systems. Typical for this malware type, it is distributed using Malware-as-a-Service (MaaL) model, which means that anyone can use the malware with minimal technical knowledge — all you need is to purchase access to a control pane from a website that sells the service.

This malware — which is written in C++ — targets Windows systems and is considered a medium impact and medium risk threat.

Having been around since 2018, Arkei has become popular among adversaries: not only is it widely used, but it has spawned several forks including Mars, Oski, and Vidar stealer, which we have covered before in the ANY.RUN trends trackers.

Arkei is capable of retrieving a variety of information from infected machines, including:

  • Form autosaves stored in the browser
  • Login and passwords
  • Files
  • Cryptocurrency wallets

Cryptocurrency owners are at the highest risk and are the main targets of Arkei. It can extract data from around 40 crypto wallet extensions, including MetaMask that accounts for over 80% of web3 wallet usage.

The stealer also targets more than 30 web browsers, including Chrome, Firefox, Microsoft Edge, Opera, Brave, and TOR.

Arkei can also target 2FA extensions, a capability it has had roughly since the beginning of 2022. It's unclear how attackers are planning to use this data, but it's certain that this development could pose new risks for both corporate and private users.

The specific data types that the malware targets depend on its configuration file — a ​​Base64-encoded file with the .PHP extensions — and will vary from campaign to campaign. The attacker can use it to set Arkei's behavior with custom rules, and target specific information.

It is important to note that Arkei terminates execution on machines from the ex-USSR regions.

The stealer identifies the region by accessing the language identifier of the Region Format setting. This behavior is typical for malware originating from the ex-USSR territories, which gives an insight into Arkei’s origin.

Arkei is equipped with multiple evasion techniques that help it avoid detection. For example, it checks that the computer name is not set to ​ “”HAL9TH”” and the username to “”JohnDoe” — these are the default settings of the Windows Defender emulator. It also checks if several DLLs are loaded in a process against a list of antivirus and emulation software.

Once it's time to gather the data, Arkei compiles its findings into a .zip archive, gives it a random 12-character name, and sends it to its control server. In addition to the information specified by the config file, it captures a system screenshot and extracts system information.

How to get more information from Arkei malware

You can obtain Arkei’s malware configurations in the ANY.RUN's sample.

Malware configuration of Arkei stealer Figure 1: Arkei configuration automatically extracted by ANY.RUN

Users can access comprehensive malware configuration data on ANY.RUN interactive online sandbox in as little as 10 seconds after starting the sandbox. There's no need to wait for the emulation to finish running.

Arkei execution process

After a system is infected, a TCP connection is established with the hacker's remote server. The server sends encoded Base64 parameters to the malware, including search path templates and file search masks. Using these parameters, the malware determines which information it needs to steal from the victim's computer.

The malware then requests the libraries necessary for its operation from the remote server. These libraries are sent as ZIP archives.

Subsequent communication with the server involves sending stolen files to the C2 server. Some threat actors use packing techniques on Arkei samples (T1027.002) to avoid detection by signatures. An example of this behavior can be seen in this task we recorded in ANY.RUN.

After launching the packed sample, the AppLaunch.exe process is created in the system, which is part of the .NET Framework. The malicious code is then injected into this process.

Distribution of Arkei

Arkei finds its victims in a number of ways. It’s delivered with malicious email campaigns in infected attachments, distributed through malicious ads, and is sometimes found in cracked software.

Adversaries use trojan horse tactics to entice potential victims into installing Arkei to their systems: social engineering techniques can be utilized, such as offering a free version of a premium software.

Arkei has also been tied to campaigns utilizing SmokeLoader — an advanced modular malware used to gain an initial foothold in the system and drop other executables. Although Smoke Loader, as you probably have guessed from its name, is primarily used as a loader, it can be armed with information stealing functionality itself — double the threat, when used together with Arkei.

Conclusion

Arkei is a that poses a significant risk to users' sensitive data, particularly crypto wallets.

But users can keep their login and password information, files, and 2FA data secure by following these best practices:

  • Avoiding clicking on suspicious links
  • Being vigilant with emails from unknown senders
  • Staying clear from lurid ads
  • Being mindful where they download software from

You can identify and analyze threats like Arkei — and more — in a matter of minutes using ANY.RUN’s interactive sandbox. Sign up for a demo!

HAVE A LOOK AT

Adwind screenshot
Adwind
adwind trojan
Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
Amadey screenshot
Amadey
amadey
Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
WarZone screenshot
WarZone
warzone avemaria stealer trojan rat
WarZone RAT is a remote access trojan, which is written in C++ and offered as a malware-as-a-service. It packs a wide range of capabilities, from stealing victims’ files and passwords to capturing desktop activities. WarZone RAT is primarily distributed via phishing emails and receives regular updates from its C2.
Read More
Azorult screenshot
Azorult
azorult trojan rat
AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat.
Read More