Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
77
Global rank
64 infographic chevron month
Month rank
80 infographic chevron week
Week rank
0
IOCs

Arkei is a stealer type malware capable of collecting passwords, autosaved forms, cryptocurrency wallet credentials, and files.

Stealer
Type
ex-USSR
Origin
21 May, 2018
First seen
6 August, 2026
Last seen
Also known as
ArkeiStealer

How to analyze Arkei with ANY.RUN

Type
ex-USSR
Origin
21 May, 2018
First seen
6 August, 2026
Last seen

IOCs

IP addresses
172.211.123.248
48.209.138.189
57.153.246.3
48.192.1.64
149.154.167.99
135.233.95.144
23.52.181.141
95.100.102.101
40.126.31.3
74.178.240.51
162.159.36.2
2.16.241.207
185.252.215.142
48.209.138.168
52.123.243.83
150.171.28.11
3.221.195.177
34.36.200.111
40.126.32.133
2.16.183.15
Hashes
42ba655e5b635698995a588f4dd39147be867a0c4b45fd49edc65982b12b9531
b6fad3bf2adba7c77641ee1a17ff4cd9e5e9b14bac1b855346c91a286e517504
9077b41d743ed6af51cd9b8aedaebb6d1e0e6217825635a1aa9451994efaff0f
f1ee3b2de54ee588813a7dbffca7e7607bbb769c763cdf73ccd600e06346fe1d
172276c875a496c173b349e24f7dec66ddda24f6a424120a13de73ef5e70ba07
eb8fc39f2551834010f3748d81e5f842a1b4e27adb87e425b764bb9152b55cb1
ad556989f6e4a683d9668e41d2d7175b7b46847c2eef26188b9075fc600d0132
f1f0c46ed4c136149fd57d9cae512242a023e14dd13d7c633bb4f7bf9ed71343
17b6e7689e333fea42b19d817427cecf95b86a340bb0af5babba3ab25e6a1b40
9729e2ae73b15871db606a18a48b8674ce2bae35d76a511d3510c4a9db2385ef
e9a93618225cb41cc154ada8e86696f461479d4d553d773d8044901e3cab26eb
f76ba06b70927aa15dffcd8dc0604c5e7a7c6e5ba7a91a6faf807b769b54c85d
68a898d8fc09b12bccb1606df2f48f184af82299f29767f6c3df24f29a2194b3
098a849ddfbe1afd6c4e54c42deecd31d32c12da507916ce0ecc88947bc8a70a
3ff9aa61c36a1ba3b7b46e7e73eda89695ab5f3f6263afe2594dcb91d50b9a64
8187fd0dbb6fa9650c17387ad91923ecf07ed0ffcf1ab2fd6d5514b822f2ab4b
b00dd75d282e11a2067bb8341c9c2b4a1c2ae5db3029e584d92a4549fb784d48
20ba365275e4972f1a68588c821cd1ec88656349633d4598a1dec93498d5638e
85d7a5ef7867ab572048c9a4f422526f249da11f3236e8763a737d66df08e096
1b3949401e310a5967a4c108bb9be49e28e69f73095ad088f783035e8f22d28f
Domains
settings-win.data.microsoft.com
google.com
self.events.data.microsoft.com
t.me
activation-v2.sls.microsoft.com
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
www.bing.com
go.microsoft.com
slscr.update.microsoft.com
login.live.com
btloader.com
pixel.rubiconproject.com
www.google-analytics.com
www.google.de
edge.microsoft.com
panel.com
script-api.ccgateway.net
cdn.jsdelivr.net
URLs
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://t.me/kkkshshs
http://185.252.215.142/1281
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://login.live.com/rst2.srf
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://clients2.google.com/time/1/current?cup2key=8:glx6g5r5l_lkrex_uavc7y44lo_ytnbym4w7jcxr80a&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://www.mediafire.com/file/ntoloy3hmm1scp2/oski+stealer+2026+feb+update.zip/file
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://cmp.gatekeeperconsent.com/min.js
https://the.gatekeeperconsent.com/cmp.min.js
https://privacy.gatekeeperconsent.com/tcf2_stub.js
https://the.gatekeeperconsent.com/v2/cmp.js?v=471
https://btloader.com/tag?o=5678961798414336&upapi=true
https://www.googletagmanager.com/gtag/js?id=ua-829541-1
Last Seen at
Last Seen at

Recent blog posts

post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 326
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 14459
comments 0
post image
Safeguarding 200M Users: How ChongLuaDao Scal...
watchers 7510
comments 0

What is Arkei malware

Arkei is a stealer designed to exfiltrate information from infected systems. Typical for this malware type, it is distributed using Malware-as-a-Service (MaaL) model, which means that anyone can use the malware with minimal technical knowledge — all you need is to purchase access to a control pane from a website that sells the service.

This malware — which is written in C++ — targets Windows systems and is considered a medium impact and medium risk threat.

Having been around since 2018, Arkei has become popular among adversaries: not only is it widely used, but it has spawned several forks including Mars, Oski, and Vidar stealer, which we have covered before in the ANY.RUN trends trackers.

Arkei is capable of retrieving a variety of information from infected machines, including:

  • Form autosaves stored in the browser
  • Login and passwords
  • Files
  • Cryptocurrency wallets

Cryptocurrency owners are at the highest risk and are the main targets of Arkei. It can extract data from around 40 crypto wallet extensions, including MetaMask that accounts for over 80% of web3 wallet usage.

The stealer also targets more than 30 web browsers, including Chrome, Firefox, Microsoft Edge, Opera, Brave, and TOR.

Arkei can also target 2FA extensions, a capability it has had roughly since the beginning of 2022. It's unclear how attackers are planning to use this data, but it's certain that this development could pose new risks for both corporate and private users.

The specific data types that the malware targets depend on its configuration file — a ​​Base64-encoded file with the .PHP extensions — and will vary from campaign to campaign. The attacker can use it to set Arkei's behavior with custom rules, and target specific information.

It is important to note that Arkei terminates execution on machines from the ex-USSR regions.

The stealer identifies the region by accessing the language identifier of the Region Format setting. This behavior is typical for malware originating from the ex-USSR territories, which gives an insight into Arkei’s origin.

Arkei is equipped with multiple evasion techniques that help it avoid detection. For example, it checks that the computer name is not set to ​ “”HAL9TH”” and the username to “”JohnDoe” — these are the default settings of the Windows Defender emulator. It also checks if several DLLs are loaded in a process against a list of antivirus and emulation software.

Once it's time to gather the data, Arkei compiles its findings into a .zip archive, gives it a random 12-character name, and sends it to its control server. In addition to the information specified by the config file, it captures a system screenshot and extracts system information.

How to get more information from Arkei malware

You can obtain Arkei’s malware configurations in the ANY.RUN's sample.

Malware configuration of Arkei stealer Figure 1: Arkei configuration automatically extracted by ANY.RUN

Users can access comprehensive malware configuration data on ANY.RUN interactive online sandbox in as little as 10 seconds after starting the sandbox. There's no need to wait for the emulation to finish running.

Arkei execution process

After a system is infected, a TCP connection is established with the hacker's remote server. The server sends encoded Base64 parameters to the malware, including search path templates and file search masks. Using these parameters, the malware determines which information it needs to steal from the victim's computer.

The malware then requests the libraries necessary for its operation from the remote server. These libraries are sent as ZIP archives.

Subsequent communication with the server involves sending stolen files to the C2 server. Some threat actors use packing techniques on Arkei samples (T1027.002) to avoid detection by signatures. An example of this behavior can be seen in this task we recorded in ANY.RUN.

After launching the packed sample, the AppLaunch.exe process is created in the system, which is part of the .NET Framework. The malicious code is then injected into this process.

Distribution of Arkei

Arkei finds its victims in a number of ways. It’s delivered with malicious email campaigns in infected attachments, distributed through malicious ads, and is sometimes found in cracked software.

Adversaries use trojan horse tactics to entice potential victims into installing Arkei to their systems: social engineering techniques can be utilized, such as offering a free version of a premium software.

Arkei has also been tied to campaigns utilizing SmokeLoader — an advanced modular malware used to gain an initial foothold in the system and drop other executables. Although Smoke Loader, as you probably have guessed from its name, is primarily used as a loader, it can be armed with information stealing functionality itself — double the threat, when used together with Arkei.

Conclusion

Arkei is a that poses a significant risk to users' sensitive data, particularly crypto wallets.

But users can keep their login and password information, files, and 2FA data secure by following these best practices:

  • Avoiding clicking on suspicious links
  • Being vigilant with emails from unknown senders
  • Staying clear from lurid ads
  • Being mindful where they download software from

You can identify and analyze threats like Arkei — and more — in a matter of minutes using ANY.RUN’s interactive sandbox. Sign up for a demo!

HAVE A LOOK AT

JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More