Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
130
Global rank
128 infographic chevron month
Month rank
122 infographic chevron week
Week rank
0
IOCs

Exela Stealer is an infostealer malware written in Python. It is capable of collecting a wide range of sensitive information from compromised systems and exfiltrating it to attackers over Discord. It is frequently used to steal browser data, and obtain session files from various applications, including gaming platforms, social media platforms, and messaging apps.

Stealer
Type
Unknown
Origin
1 May, 2023
First seen
28 August, 2026
Last seen

How to analyze Exela Stealer with ANY.RUN

Type
Unknown
Origin
1 May, 2023
First seen
28 August, 2026
Last seen

IOCs

IP addresses
200.43.178.237
222.25.196.3
117.72.242.9
210.243.136.114
210.40.225.135
210.183.225.16
159.254.4.233
129.28.245.228
165.57.191.50
134.131.43.0
82.163.137.66
33.59.140.89
35.234.67.204
169.20.110.100
27.37.3.185
96.85.140.112
210.127.39.250
192.95.200.170
196.190.220.153
33.59.187.160
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
a17fcf0a2f50e2d495e4f90ce263410edc183add6c62699a2facbccf60410f74
69b61b2c00323cea3686315617d0f452e205dae10c47e02cbe1ea96fea38f582
ba25fefad8a545281ae6f99515926717ebe8c1146805795bedd32041192a0688
61450bd6bc6590236b1df56e1594b12ae174496357a49b5963c41d0d1465d66f
84b900dbd7fa978d6e0caee26fc54f2f61d92c9c75d10b35f00e3e82cd1d67b4
5bdd60c20bf45fbb96d6df9a27040a12b2a131bbf81445bb291a3d4c237c3638
0bda727d28b1303c50ca05c71522af79a0dc714338ef57634682171327fc772f
4055d1b9e553b78c244143ab6b48151604003b39a9bf54879dee9175455c1281
f5d002bfe80b48386a6c99c41528931b7f5df736cd34094463c3f85dde0180bf
326bcb85652c67780d0193d78d5bab30e3668e6bcbcffcff304751b2f4518f54
28afa9302c5708c74af235d477cb13c0dd1358f2ea17f3d08a4c02b6fe4a0939
408ad45577c7d5d163c0019fa9f900fcbf132a1183dbc58cf14cb83e195c6bfa
99e6eb0215c652fe9e9b2f91db5759286cd04f837ce09b331f88f804b0be5195
c9d5bb7022889629ac75a5f7b56779c5ed3d4facea41effd1616039d95bbbc5d
2c8a0014e2b00ecece9639af449fee4c8b8af95a2b9e1589715168fdc9f14600
21ff1de20ee321daf3b67e5d4b8cbfa34cce3af19276abd7f8ae3dcf21e9e971
e01730fda4af0b4efcd46b2ed11ec9a6f46335f0da943ec574de0c0c81e87e62
8db6544480798c1f7e62868ab5f60722bba009cd2b7ca656dd72f40a51b4ebdd
63bcd09c106915cebed1ab7ed14f59b568ebb338e25c876b98580e4578be0cc2
Domains
ip-api.com
pastebin.com
slscr.update.microsoft.com
edge-consumer-static.azureedge.net
urlhaus.abuse.ch
www.google.com
0022a601.pphost.net
matthewsigmondv5.pages.dev
github.com
safeuploadz.com
fonts.googleapis.com
resolver.disbalancer.com
qiniuyunxz.yxflzs.com
mogimall.com
edge-mobile-static.azureedge.net
c.pki.goog
settings-win.data.microsoft.com
cnr.microsoft-telemetry.at
open.spotify.com
gitlab.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://urlhaus.abuse.ch/downloads/text_online/
http://144.172.71.105:1338/nova_flow/patcher.exe
https://www.blackhattoolz.com/licensing/updates/addmefast%20bot.exe
https://raw.githubusercontent.com/leetcipher/malware.development/main/process-injection/process-injection.exe
https://raw.githubusercontent.com/haa15/driver-shitty/main/kdmapper_release.exe
https://github.com/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol11.exe
https://release-assets.githubusercontent.com/github-production-release-asset/1055902550/c1473cf5-ad3b-426a-8984-5bc61976d274?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-08-28t12%3a24%3a38z&rscd=attachment%3b+filename%3dlol11.exe&rsct=application%2foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-08-28t11%3a23%3a43z&ske=2026-08-28t12%3a24%3a38z&sks=b&skv=2018-11-09&sig=c55xqnra0h1y9qkw2iqmtw5pab2x6spaimkomqi6niy%3d&jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc4nzkxnzizmiwibmjmijoxnzg3ote2otmylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.xx_s-1rm4wy4vlc8piwgob44k-01m9e-y4y99trt0by&response-content-disposition=attachment%3b%20filename%3dlol11.exe&response-content-type=application%2foctet-stream
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://144.172.71.105:1338/nova_flow/patcher.exe?hash
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://45.138.16.51/bin/screenconnect.clientsetup.exe
http://192.162.199.149/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe
http://0022a601.pphost.net/threatsim/exe/640.exe
http://0022a601.pphost.net/threatsim/exe/xerox01_pdf.exe
http://119.193.158.215/center.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4905
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 11329
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 13623
comments 0

What is malware: Exela Stealer?

Exela Stealer, an open-source Python-based stealer, has been extensively used to target victims’ Discord accounts and browsers to steal sensitive data. This malware was first uploaded to GitHub in May 2023 and has since evolved with additional features.

Despite providing a note about the program being intended for educational purposes, the creators also sell a paid version of the software, which, according to their claims, possesses superior evasion capabilities. This premium version of Exela Stealer is distributed using the common malware-as-a-service (MaaS) model based on a subscription similar to other malware families. Such examples include Formbook and XWorm.

However, according to the message posted on February 10, 2024, in their Telegram channel, the malware’s developer announced that both the free and paid versions would not receive any further updates.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Exela Stealer malicious software technical details

Exela Stealer is a sophisticated tool that can collect a wide range of sensitive information from compromised systems:

  • Discord Injection: Exela Stealer can inject malicious code into the Discord client to obtain tokens, passwords, and email addresses.
  • Browser Data: The stealer can acquire various data from web browsers, cookies, including bookmarks, passwords, browsing history, and downloaded files.
  • Screenshot Capture: The stealer can capture screenshots from all monitors connected to the compromised system. This feature allows the attacker to visually monitor the user's activities.
  • Cryptocurrency and Wallet Information: Exela Stealer can scan the system to obtain cryptocurrency and wallet information stored in web browsers. This can potentially allow the attacker to misappropriate the user's cryptocurrency funds.
  • Autofill Data: The stealer can gain access to autofill data from web browsers. This includes personal information, such as names, addresses, phone numbers, and email addresses.
  • Session Files: Exela Stealer can get hold of session files from various applications, including Telegram, Uplay, Epic Games, Growtopia, Instagram, Twitter, TikTok, Twitch, Spotify, Riot Games, Reddit, Roblox, and Steam. This can provide the attacker with unauthorized access to the user's accounts on these platforms.

It can display fake error messages, as well as detect processes and system settings related to debugging or virtualization. For instance, it can determine the machine’s Universally Unique Identifier (UUID) and then check if it matches any entry on its list of known UUIDs.

Exela Stealer ensures its persistence by enabling automatic execution upon the user’s system login. It can either add an entry to the Windows Registry or create scheduled tasks.

Exela Stealer exfiltrates the data collected from compromised systems via a Discord webhook URL, sending it to the attacker.

Exela Stealer attack execution process

To observe the behavior of Exela Stealer on an actual system, we can upload its sample to the ANY.RUN sandbox for in-depth analysis.

Exela Stealer operates through a sophisticated execution chain involving several stages. Initially, it may be delivered via phishing emails or through compromised websites. Once a user unwittingly downloads and executes the malware, it establishes persistence by modifying system settings or creating new autostart entries in the Windows registry.

Next, Exela Stealer typically employs obfuscation techniques to evade detection by security software, such as encryption or code obfuscation. It then begins its primary function of exfiltrating sensitive information from the infected system, such as login credentials, credit card numbers, or personal documents.

Finally, the stolen data is transmitted to a remote command and control server controlled by the attackers, where it can be used for various malicious purposes, including identity theft or financial fraud. Throughout this execution chain, Exela Stealer aims to operate discreetly to maximize its effectiveness and avoid detection by security measures.

Exela processes shown in ANY.RUN Exela Stealer's processes demonstrated in ANY.RUN

In our example, we can observe that the malware utilizes various system utilities to obtain information about the list of running processes. Additionally, it conducts system language discovery by checking the languages supported by the infected system, modifies file attributes, and gathers various other details about the infected system and its users.

Exela Stealer malware distribution methods

Since the free version of the malware is widely accessible, any ill-intentioned individual can use it to attempt to infect machines of other users. Exela Stealer usually ends up on victims’ computers through phishing emails or messages. Attackers craft these to appear as if they were written by legitimate entities, such as trusted organizations. These messages often contain malicious attachments that, after executing, cause the Exela stealer infection on their machine.

Conclusion

Exela Stealer poses a significant threat to digital security due to its sophisticated tactics for stealing sensitive information. Its ability to leverage legitimate platforms like Discord and its continuous evolution underscore the importance of having proper security tools.

ANY.RUN is a cloud-based sandbox for detecting and analyzing threats, such as Exela Stealer, that offers detailed reports on their technical characteristics. The service lets you examine any suspicious file and check potentially harmful URLs, ensuring informed decision-making and prompt deletion of any malware, as well as proper protection of your infrastructure.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More