Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now

Mars Stealer

117
Global rank
114 infographic chevron month
Month rank
98 infographic chevron week
Week rank
0
IOCs

Mars Stealer is a malware program designed to steal sensitive information from infected systems. It can access browser credentials, cryptocurrency wallets, and system information. The malware utilizes advanced evasion techniques and transmits stolen data securely through a C&C server.

Stealer
Type
ex-USSR
Origin
1 June, 2021
First seen
9 January, 2025
Last seen

How to analyze Mars Stealer with ANY.RUN

Type
ex-USSR
Origin
1 June, 2021
First seen
9 January, 2025
Last seen

IOCs

Domains
dispatchweekly.com14baef17b6d04c23.php
URLs
http://kenesrakishev.net/wp-admin/admin-ajax.php
http://www.moscow-post.ru/bark/wpadmin/admin.php
http://kenesrakishev.net/wp-includes/pomo/po.php
http://kenesrakishev.net/wp-load.php
http://rakishevkenes.com:443/wp-admin/admin-ajax.php
http://rakishevkenes.com/wp-admin/admin-ajax.php
http://mars.mhsorteio.app.br/APwpnHWkYh.php
http://couriercare.in/18/gate.php
http://www.msk-post.com/server/init.php
http://mail.moscow-post.com/blog/blogger.php
http://gg.gemkan.online/gate.php
http://couriercare.in/2/gate.php
http://www.moscow-post.ru/ryuka/grocktack/fdzeiw.php
http://moscow-post.com/xaoniu/server/waungowangued/g.php
http://moscow-post.ru/patch/server/udryhdj.php
http://moscow-post.com/log/loger.php
http://test.moscow-post.su/log.php
http://www.moscow-post.com/wp-content/plugins/toocreate/tuzerfd.php
http://www.moscow-post.su/su/wp-content/lozzz.php
http://moscow-post.ru/blogggg/blogger.php
Last Seen at
Last Seen at

Recent blog posts

post image
Threat Intelligence Pivoting: Actionable Insi...
watchers 145
comments 0
post image
Integrate ANY.RUN Threat Intelligence Feeds w...
watchers 3092
comments 0
post image
2024 Wrapped: A Year of Growth, Innovation, a...
watchers 2238
comments 0

What is malware: Mars Stealer?

First identified in June 2021, Mars Stealer is a type of malicious software primarily focused on collecting sensitive information from browsers and cryptocurrency wallets for transmission to attackers. Written in ASM/C, the malware was initially sold through Dark Web forums as a malware-as-a-service on a subscription basis. It shared similar features with other malware like Oski Stealer, Arkei, and Vidar.

While the malware appeared to have stopped functioning in 2022, with reports of unresponsive developers, evidence suggests that the original creators of Mars Stealer remain active in 2024 and continue to exploit the malware for malicious purposes.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Mars Stealer malicious software technical details

Information theft constitutes the core focus of Mars Staler:

  • Browser Credentials: It steals login credentials from popular browsers like Firefox, Chrome, Opera, and Internet Explorer using predefined paths to locate and extract data like usernames and passwords.
  • 2FA and Crypto Extension Data: Focusing specifically on Chromium-based browsers, Mars Stealer can hijack two-factor authentication (2FA) plugins and cryptocurrency extensions.
  • Cryptocurrency Wallet Targeting: It targets popular wallets like MetaMask and Binance Wallet, seeking information such as private keys.
  • Extensive System Information Collection: Mars Stealer also gathers comprehensive system information, including IPs, OS details, software installed on compromised systems, and usernames.
  • Screenshot Capture: The malware also captures a screenshot of every infected system.

Mars Stealer establishes a secure connection with its Command & Control (C&C) server using SSL encryption. This encrypted communication channel allows the malware to receive instructions, download configurations and libraries, and exfiltrate stolen data without raising red flags. The information collected by the malware is compressed into a ZIP archive before being exfiltrated to the C&C server.

Mars Stealer employs various evasion techniques to escape detection and analysis. For instance, it masks its WinApi calls and encrypts strings. To prevent multiple instances of the malware from running concurrently, Mars Stealer creates a mutex object. The virus employs a custom file grabber with configuration parsing capabilities, allowing for flexible targeting of specific files and directories.

The malware includes a special feature that checks every machine before attempting infection to identify whether it is located in one of the countries that belong to the Commonwealth of Independent States (CIS). This likely points to the fact that the creators of Mars Stealer hail from the same region.

Mars Stealer execution process

It’s time to have a better look at Mars Stealer by uploading its sample to the ANY.RUN sandbox for closer inspection.

As perpetrators endeavor to conceal their activities, the Mars Stealer employs a deliberately straightforward execution chain to minimize visibility. Consequently, the infected operating system experiences a limited number of processes, and the malware refrains from utilizing system tools. Once the payload infiltrates the compromised system, it promptly initiates its execution.

The analyzed sample initiates a process executing all malicious activities, including data theft and communication with the Command and Control (C&C) server. Malware was detected, and the configuration was successfully extracted.

Mars config shown in ANY.RUN Mars Stealer's configuration demonstrated in ANY.RUN

Mars Stealer malware distribution methods

When it comes to distribution methods, a typical attack in the case of Mars Stealer starts from spam campaigns or fake websites advertising legitimate software. For instance, in 2022, one of the campaigns to distribute Mars Stealer used a website promoting Atomic Wallet, a popular cryptocurrency wallet. After clicking on the “download” button on the website, users would receive a .zip file which contains a sample of Mars Stealer.

The malware was also commonly dropped by loaders, malicious software designed specifically for spreading different malware families on devices they manage to infect. One of the examples here is PrivateLoader.

Conclusion

With malware infections being at an all time high, it becomes important to stay vigilant and exercise caution when encountering any suspicious emails, websites, or software downloads to avoid falling victim to Mars Stealer or similar malware threats, as well as to maintain protection of your infrastructure.

ANY.RUN, a cloud-based sandbox, offers accurate threat detection, along with detailed reports on their technical characteristics. It lets you scan any suspicious file and check potentially malicious URLs to ensure informed decision-making and timely removal of any traces of the malware.

Try ANY.RUN for free – register now!

HAVE A LOOK AT

Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
Sality screenshot
Sality
sality
Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.
Read More
Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More