Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mars Stealer

143
Global rank
142
Month rank
154 infographic chevron week
Week rank
0
IOCs

Mars Stealer is a malware program designed to steal sensitive information from infected systems. It can access browser credentials, cryptocurrency wallets, and system information. The malware utilizes advanced evasion techniques and transmits stolen data securely through a C&C server.

Stealer
Type
ex-USSR
Origin
1 June, 2021
First seen
3 August, 2026
Last seen

How to analyze Mars Stealer with ANY.RUN

Type
ex-USSR
Origin
1 June, 2021
First seen
3 August, 2026
Last seen

IOCs

IP addresses
95.100.102.9
150.171.28.11
172.66.2.5
150.171.22.17
150.171.109.193
48.192.1.64
149.137.141.9
74.179.77.204
95.100.102.101
57.153.246.3
172.211.123.249
150.171.109.34
48.209.138.168
23.48.23.156
2.16.204.158
74.178.240.51
23.59.18.102
142.251.14.132
150.171.109.194
92.223.97.79
Hashes
bd7198c76594a6ed1147412a4e37d1ae258d1fd9358d96ded9b524dbeea7bc30
58665da49b1ebca85993de6e799f423b4589359b2eb43cb6b8bb81223fc02b10
3fe11c2a0b4c2b50035c224d2e6c87ba19a05663811c459d4e3a2f780aede957
166ffee51259387356bdadeb22cdc7d053fc89ef6f51ae3c774d522a4dfaf08e
e4c44b7ce8a72720e2ab8b38b8885fca36dda04daa14ae37909bbd501d853074
4a5179c7a54ce4395781fbb535bbffb03b4bdbd56046f9209d4f415b1ad5b19c
d29f945dba8413eb510d42b8b4bfe4e2bdf2bd81158254c4279d056cb0d4b5e2
75bfedebfb9cc57d3ed2a6fc640c7540195604bacbd8cc8301b3a053deed199a
49b0a50005440417bd679d03d4d78f9ba0d1c457285c97e94f36e56b1e8b623b
f045097a337487211f80bfeaa3391aac99a5b54950380bd32c3d1c96b512f0c8
1f85c9e9a1a0def09db35b63b9aae2a3c4f92202d701322621c8cfddf8880162
9301b5300fa18b50f774512c3549ded45bf41c30359d1824ced7cca0cc75e216
0153d9f72dcd5563daedd27f7e0407aee3f39fef74e8d75951777da986e05257
a20c8a35e42004c904e1a06115a9657b170d8090ebe26e96592139e1c8a9e358
140a569d8ed63a59005323a6e06b704a908741c17e0b46b191b2316e2a62e1f7
2c98e8d0330de0bf8853cd0e6e8cf0e6155ca4a8bc1adfaabc0b53534e76e6b7
c166eb24c0313ce21f028765caed483650eeff9db59c34243b3fe933999deb0e
77853ee80bc5ed90becfbae3b00d2b8088985e0933a3bf389255f44b947223ff
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
3a5078b626e41d20117d260d8b825b039884cfe062c6d462432216d9b07d82b5
Domains
activation-v2.sls.microsoft.com
watson.events.data.microsoft.com
crl.microsoft.com
copilot.microsoft.com
go.microsoft.com
clients2.googleusercontent.com
s3.us-east-005.backblazeb2.com
www.microsoft.com
ocsp.digicert.com
www.bing.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
api.edgeoffer.microsoft.com
google.com
edge.microsoft.com
edge-consumer-static.azureedge.net
edge-mobile-static.azureedge.net
update.googleapis.com
fe3cr.delivery.mp.microsoft.com
edge-cloud-resource-static.azureedge.net
client.wns.windows.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wg7ewxkxq4w57nwbhjwiuyhqx6zg5mhgxbhsrnqz5ms&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://s3.us-east-005.backblazeb2.com/vx-underground-main/builders/mars%20stealer/mars%20stealer%20builder.h.7z?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=005e2c099359ccf0000000004%2f20260803%2fus-east-1%2fs3%2faws4_request&x-amz-date=20260803t143424z&x-amz-expires=3600&x-amz-signedheaders=host&x-amz-signature=35a6f96a1be68a4a813f98a45af057a7d4b3fcd8e0b4c6d7f301b28d85b1c09b
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d227%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://update.googleapis.com/service/update2/json?cup2key=14:kvovqn2uzvzjenjrzl76levnkxpov3cjbvp9okjqhse&cup2hreq=095702caf84e776000939891fe03bde586cb42e6851cb2dcc1abdfcbc5e03986
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://clients2.googleusercontent.com/crx/blobs/auu14h9lifl_xdfovyc6ev9d9ia6qcy2fpggd1uevuk_yoqwcsmd13fexvuvu2cn93z41_hou8y7vuivvhjkvqkxhviwy8eqaszi6uvsh8cwzz02zvegbus0d2hnwvroeqeaxlka5cc_zznn-sn4gcvn46um6ojs-psr/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_108_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
Last Seen at
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 8245
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 3788
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 37063
comments 0

What is malware: Mars Stealer?

First identified in June 2021, Mars Stealer is a type of malicious software primarily focused on collecting sensitive information from browsers and cryptocurrency wallets for transmission to attackers. Written in ASM/C, the malware was initially sold through Dark Web forums as a malware-as-a-service on a subscription basis. It shared similar features with other malware like Oski Stealer, Arkei, and Vidar.

While the malware appeared to have stopped functioning in 2022, with reports of unresponsive developers, evidence suggests that the original creators of Mars Stealer remain active in 2024 and continue to exploit the malware for malicious purposes.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Mars Stealer malicious software technical details

Information theft constitutes the core focus of Mars Staler:

  • Browser Credentials: It steals login credentials from popular browsers like Firefox, Chrome, Opera, and Internet Explorer using predefined paths to locate and extract data like usernames and passwords.
  • 2FA and Crypto Extension Data: Focusing specifically on Chromium-based browsers, Mars Stealer can hijack two-factor authentication (2FA) plugins and cryptocurrency extensions.
  • Cryptocurrency Wallet Targeting: It targets popular wallets like MetaMask and Binance Wallet, seeking information such as private keys.
  • Extensive System Information Collection: Mars Stealer also gathers comprehensive system information, including IPs, OS details, software installed on compromised systems, and usernames.
  • Screenshot Capture: The malware also captures a screenshot of every infected system.

Mars Stealer establishes a secure connection with its Command & Control (C&C) server using SSL encryption. This encrypted communication channel allows the malware to receive instructions, download configurations and libraries, and exfiltrate stolen data without raising red flags. The information collected by the malware is compressed into a ZIP archive before being exfiltrated to the C&C server.

Mars Stealer employs various evasion techniques to escape detection and analysis. For instance, it masks its WinApi calls and encrypts strings. To prevent multiple instances of the malware from running concurrently, Mars Stealer creates a mutex object. The virus employs a custom file grabber with configuration parsing capabilities, allowing for flexible targeting of specific files and directories.

The malware includes a special feature that checks every machine before attempting infection to identify whether it is located in one of the countries that belong to the Commonwealth of Independent States (CIS). This likely points to the fact that the creators of Mars Stealer hail from the same region.

Mars Stealer execution process

It’s time to have a better look at Mars Stealer by uploading its sample to the ANY.RUN sandbox for closer inspection.

As perpetrators endeavor to conceal their activities, the Mars Stealer employs a deliberately straightforward execution chain to minimize visibility. Consequently, the infected operating system experiences a limited number of processes, and the malware refrains from utilizing system tools. Once the payload infiltrates the compromised system, it promptly initiates its execution.

The analyzed sample initiates a process executing all malicious activities, including data theft and communication with the Command and Control (C&C) server. Malware was detected, and the configuration was successfully extracted.

Mars config shown in ANY.RUN Mars Stealer's configuration demonstrated in ANY.RUN

Mars Stealer malware distribution methods

When it comes to distribution methods, a typical attack in the case of Mars Stealer starts from spam campaigns or fake websites advertising legitimate software. For instance, in 2022, one of the campaigns to distribute Mars Stealer used a website promoting Atomic Wallet, a popular cryptocurrency wallet. After clicking on the “download” button on the website, users would receive a .zip file which contains a sample of Mars Stealer.

The malware was also commonly dropped by loaders, malicious software designed specifically for spreading different malware families on devices they manage to infect. One of the examples here is PrivateLoader.

Conclusion

With malware infections being at an all time high, it becomes important to stay vigilant and exercise caution when encountering any suspicious emails, websites, or software downloads to avoid falling victim to Mars Stealer or similar malware threats, as well as to maintain protection of your infrastructure.

ANY.RUN, a cloud-based sandbox, offers accurate threat detection, along with detailed reports on their technical characteristics. It lets you scan any suspicious file and check potentially malicious URLs to ensure informed decision-making and timely removal of any traces of the malware.

Try ANY.RUN for free – register now!

HAVE A LOOK AT

BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More