Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DeerStealer

92
Global rank
128 infographic chevron month
Month rank
162 infographic chevron week
Week rank
0
IOCs

DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.

Stealer
Type
Unknown
Origin
1 June, 2024
First seen
19 August, 2026
Last seen

How to analyze DeerStealer with ANY.RUN

Type
Unknown
Origin
1 June, 2024
First seen
19 August, 2026
Last seen

IOCs

IP addresses
142.251.13.94
149.154.167.99
172.64.149.23
64.89.163.22
104.21.22.216
125.88.255.55
103.7.55.233
196.251.107.186
91.92.242.236
61.249.139.64
36.99.188.97
77.93.153.170
62.60.226.185
185.199.108.133
120.48.115.29
172.67.189.7
134.122.189.98
172.67.69.249
89.106.83.205
68.66.226.105
Hashes
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0
dc58d8ad81cacb0c1ed72e33bff8f23ea40b5252b5bb55d393a0903e6819ae2f
60c06e0fa4449314da3a0a87c1a9d9577df99226f943637e06f61188e5862efa
ba25fefad8a545281ae6f99515926717ebe8c1146805795bedd32041192a0688
8eee9284e733b9d4f2e5c43f71b81e27966f5cd8900183eb3bb77a1f1160d050
2d79af8e1ff3465703e1dc73d3ef2182fd269ea2609c8afabdf1b80693405c1d
d769fafa2b3232de9fa7153212ba287f68e745257f1c00fafb511e7a02de7adf
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
ea7fd75e2bb069699d4da09f3601d70ca8e401f58949178cdbf2c5928720daa1
eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
882115c95dfc2af1eeb6714f8ec6d5cbcabf667caff8729f42420da63f714e9f
f71621c47c610e0886846cf53d955fd0e7448951f99ecc22facd47493ef97a87
b59a0e0570d2a22cd51fb51fc106913f9048f2889fc3bd94a5a51be1a5d102f9
482bd77edd55a8836f3f37edc8dfadcabddece7433b0b80675f4448ca73c411e
6a35628719ac99e69e506d0ecc37d2157b33c476455c4996d2c9a860c677bed7
77adee0261cd5a393eddd14c7206babd3b56656428739a58fbd0431b437c9dc6
10a10cf0c7d773f917b377705db45bdc399c5058ccefa656b6e63b14fe64d8c8
1c223165da67e6fd0b408f19428d4424012892d5684ba7149b58f5f5eb4fe6ce
f8708f4d86df2245b542b6fe1aeb8fdb642c168fd60c8c5e3f3004f8fc42197a
Domains
vexdico.shop
tarkioweb.com
2398.35go.net
refaccionesalma.com.mx
mitraperijinan.co.id
m.jkoa.co.kr
furystaff.tech
baolongwes.oss-ap-southeast-1.aliyuncs.com
ljr.1001gacor.org
pub-ec081eb0fab74385a17d8d77afeeda3b.r2.dev
theoremaoliveoil.com
lcportal.kbinsure.co.kr
c.pki.goog
vizyonuniversitesi.web.tr
ocsp.sectigo.com
telegram.me
manage-analytcs.org
ocsp.digicert.com
fb6390d5.infinityindians.pages.dev
settings-win.data.microsoft.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://manbipll.duckdns.org/ljezs/main.exe
http://manbipll.duckdns.org/ljezs/debug_main.exe
http://196.251.107.186/clp4.exe
http://196.251.107.186/zs/zs64.exe
http://196.251.107.186/clp.exe
http://192.162.199.149/uploads/cl1786993325592.exe
http://45.141.119.82/setup.exe
http://45.141.119.82/update.ps1
http://91.92.47.8/cw.exe
http://91.92.47.8/quis.exe
http://91.92.242.236/files-129312398/files/file_bec865d8acfd0630.exe
http://217.60.241.142/bin/support.client.exe
http://192.162.199.149/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe
http://217.60.241.142/bin/screenconnect.clientsetup.exe
http://91.92.242.236/files-129312398/files/file_6a286233562894b3.exe
http://107.175.88.87/22/goodpersonforbestthingsfor.hta
http://196.251.107.186/svbia/post.php
http://91.92.242.236/files-129312398/files/file_4b8d61b5a6f660b5.exe
http://192.162.199.186/discrete_69.7868.8_install.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2191
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6596
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10054
comments 0

What is DeerStealer malware?

DeerStealer is a relatively new info-stealing malware that emerged in 2024, targeting sensitive data like login credentials, browser history, and cryptocurrency wallet details.

Unlike more established stealers, DeerStealer has quickly gained attention due to its innovative distribution methods, including fake websites mimicking legitimate services like Google Authenticator. These sites trick users into downloading malware under the guise of security software.

The malware has been linked to malicious campaigns that target individual users as well as organizations, and it’s speculated to share similarities with other stealer malware like XFiles.

In addition to exfiltrating data, DeerStealer persists on infected systems by modifying registry keys, enabling it to survive reboots and remain active.

This persistence, combined with its focus on browser exploitation and cryptocurrency theft, makes DeerStealer a significant risk, particularly to users managing sensitive online accounts and assets.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

DeerStealer malware technical details

The primary functionality and features of DeerStealer malware include:

  • Extraction of credentials from web browsers, email clients, and cryptocurrency wallets.
  • Modification of registry keys to reinfect the system after reboot, ensuring long-term access.
  • Obfuscation techniques to avoid detection by security tools, making it harder to analyze.
  • Delivery via phishing emails, malicious Google ads, and fake websites mimicking legitimate services, including Google Authenticator sites.
  • Communication with a command-and-control server via POST requests to send stolen data, often using encrypted communication through simple XOR encryption.

In some DeerStealer campaigns, attackers use a Telegram bot to send information about infected systems, such as IP addresses and country.

When victims land on a fake website (like a Google Authenticator download page), their IP address and country are sent to a Telegram bot. This bot, named "Tuc-tuc," helps attackers track the locations of infected users and coordinate further actions.

Telegram serves as a secure and anonymous medium for logging victim data, making it easier for the attackers to monitor their phishing campaigns without detection.

DeerStealer execution process

To see how DeerStealer operates, let’s upload its sample to the ANY.RUN sandbox.

DeerStealer is commonly distributed via fake websites that mimic legitimate services, such as Google Authenticator. When users attempt to download the application from these sites, their information, such as IP address and country, is sent to a Telegram bot.

The malware itself is hosted on platforms like GitHub and is designed to run directly in memory without leaving traces on disk.

DeerStealer fake website Fake website mimicking Google Authenticator analyzed inside ANY.RUN’s sandbox

Upon execution, it launches a Delphi-based application that serves as a launcher for the final payload.

To evade detection, the payload employs obfuscation techniques and runs entirely in memory, making it difficult for traditional antivirus solutions to identify.

Before initiating its malicious activities, DeerStealer performs checks to confirm it's not operating in a sandbox or virtual environment. It collects hardware identifiers (HWID) and transmits them to its command and control (C2) server. If the checks are passed, the malware retrieves a list of target applications and keywords from the server.

DeerStealer process graph DeerStealer process graph displayed in the ANY.RUN sandbox

DeerStealer scans the infected system for sensitive information, such as cryptocurrency wallet credentials, browser-stored passwords, and other personal data. The stolen data is organized into a structured format, often JSON, before being exfiltrated.

The exfiltration occurs through POST requests, typically sent over encrypted channels to bypass network monitoring tools. To maintain persistence, DeerStealer may establish scheduled tasks or modify startup configurations, enabling it to execute automatically upon system reboot.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

DeerStealer malware distribution methods

DeerStealer is primarily distributed through various deceptive techniques that aim to trick users into downloading malware. Some of the key distribution methods include:

  • Phishing emails: Attackers send emails that appear legitimate, often containing malicious attachments or links. These attachments can be disguised as Word documents or compressed files (e.g., .zip or .rar), which, once opened, deploy the malware.
  • Malvertising: Cybercriminals use malicious advertisements that romote legitimate services like Google Authenticator. When users click on these ads, they are redirected to fraudulent websites that prompt them to download DeerStealer.
  • Fake websites: Attackers create websites that mimic legitimate services, particularly focusing on fake Google Authenticator sites. These websites trick users into downloading infected files disguised as legitimate software.
  • Software cracks: It has also been observed in pirated software downloads, where users download what appears to be legitimate software, only to infect their systems with DeerStealer.

Gathering threat intelligence on DeerStealer malware

To collect up-to-date intelligence on DeerStealer, you can utilize Threat Intelligence Lookup from ANY.RUN.

This tool gives access to a comprehensive database filled with insights from millions of malware analysis sessions. Using over 40 customizable search parameters, such as IPs, domains, file names, and process artifacts, it allows you to uncover important details about threats like DeerStealer.

DeerStealer TI Lookup results Search results for DeerStealer in Threat Intelligence Lookup

For instance, by searching for DeerStealer’s name or using a related indicator, such as a domain or process artifact (threatName:"DeerStealer", Threat Intelligence Lookup will display all relevant samples and sandbox results associated with the malware.

Get your 14-day free trial of Threat Intelligence Lookup along with the ANY.RUN sandbox.

Conclusion

DeerStealer is a serious threat, capable of stealing login credentials, browser data, and cryptocurrency information. Its distribution through fake websites makes it difficult to detect. It’s important to analyze suspicious files and URLs to protect against DeerStealer and similar malware.

ANY.RUN provides a real-time sandbox for analyzing malware behavior and allows its users to quickly identify threats, gathering key indicators of compromise (IOCs)

Sign up for a free ANY.RUN account today and start analyzing all the emerging threats with no limits!

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More