Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Meduza Stealer

122
Global rank
141 infographic chevron month
Month rank
151 infographic chevron week
Week rank
0
IOCs

Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.

Stealer
Type
Unknown
Origin
1 June, 2023
First seen
24 February, 2026
Last seen

How to analyze Meduza Stealer with ANY.RUN

Type
Unknown
Origin
1 June, 2023
First seen
24 February, 2026
Last seen

IOCs

IP addresses
188.114.97.3
38.91.107.229
38.91.107.2
14.0.37.128
46.34.51.181
77.239.121.89
172.67.209.38
172.67.199.82
172.67.167.216
172.67.213.74
172.67.148.242
104.21.20.77
45.91.94.210
104.21.4.14
104.21.34.31
104.21.55.141
104.21.85.251
104.21.21.153
147.45.44.212
89.22.239.174
Domains
hotsocks.ws
hotsocks.biz
hector.su
avscan.net
binsoficial666.activo.mx
faceless.cc
bclub.cm
b1ackstash.cc
c0nnect.pro
ghostsocks.net
xleet.pw
stashpatrick.io
vn5socks.net
spamir.fr
alarti.ru
openmailertrack.com
usps-mypackage.com
royalescort.net
tracking-usps.com
vpn567288128.softether.net
Last Seen at

Recent blog posts

post image
Ready for macOS Threats: Expanding Your SOC’s...
watchers 1355
comments 0
post image
How to Reduce MTTR in Your SOC with Better Th...
watchers 554
comments 0
post image
Lazarus, AI, and Trust Abuse: Top Enterprise...
watchers 1608
comments 0

What is Meduza Stealer?

Meduza Stealer is a sophisticated piece of information-stealing malware designed to target a wide range of sensitive data on infected systems. Its execution process is systematic, involving several key stages that ensure efficient data collection while evading detection.

First discovered in 2023, it has quickly become notorious for its wide-reaching capabilities, targeting over 100 web browsers and 107 cryptocurrency wallets. Meduza can collect data such as login credentials, browser history, bookmarks, autocomplete fields, and even sensitive information stored in applications like Telegram, Discord, and Steam.

It has an advanced structure that allows it to operate stealthily, using several techniques to evade detection by antivirus programs and other security measures.

Meduza Stealer is distributed through a Malware-as-a-Service (MaaS) model on underground forums and Telegram, making it accessible to cybercriminals with varying technical skill levels. For a subscription fee, attackers can customize Meduza Stealer to suit their needs.

Once it infects a system, the malware establishes communication with a Command and Control (C2) server to upload stolen data. A web panel allows attackers to view the exfiltrated information, which can include operating system details, IP addresses, and the nature of the stolen data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Meduza Stealer technical details

Meduza Stealer collects a wide variety of sensitive data, including login credentials, browsing history, cookies, and cryptocurrency wallets.

Here are the main technical functionalities of this malware:

  • Establishes a connection with a command-and-control server to exfiltrate stolen data.
  • Alters system registry keys to ensure persistence after rebooting the infected machine.
  • Uses encryption techniques to protect the stolen data during transmission to evade detection.
  • Doesn’t employ obfuscation techniques, making it harder to identify and trace.
  • Attackers can customize payloads via a web panel, adjusting the malware for specific campaigns.
  • Focuses on stealing data from browsers, cryptocurrency wallets, and messaging platforms like Telegram and Discord.
  • Extracts data from various password management tools, giving attackers access to stored credentials.
  • Utilizes anti-debugging techniques to avoid detection in sandbox environments.
  • Operates silently in the background to avoid raising suspicion from the victim.

Meduza Stealer performs geolocation checks on the infected system using the victim's IP address. If the location matches a region in its exclusion list, the malware halts its operations, thus avoiding detection and action in certain regions.

This malware can be delivered via malicious files like .exe, .doc, and .zip attachments, typically spread through phishing emails and malicious links.

Meduza stealer execution process

To see how Meduza stealer operates, let’s upload its sample to the ANY.RUN sandbox.

Upon infiltrating a system, Meduza first conducts a geolocation check using the victim's IP address. If the location matches an entry on its predefined exclusion list, the malware immediately halts its operations. If the check is passed, Meduza attempts to connect to its Command and Control (C2) server, which is one of the most crucial steps.

Meduza in ANY.RUN sandbox Process graph of Meduza Stealer inside ANY.RUN’s sandbox

If the server is unreachable, the malware terminates its process. Unlike many other stealers that delay contacting their C2 servers until after data collection, Meduza establishes this connection early in its execution.

Once connected to the C2 server, Meduza begins collecting extensive information from the infected machine, including:

  • System information: Details about the operating system and hardware.
  • Browser data: Login credentials, browsing history, cookies, and bookmarks from targeted browsers.
  • Password managers: Data from various password management applications.
  • Cryptocurrency wallets: Information from supported cryptocurrency wallet extensions.
  • Installed applications: Information about installed games and desktop applications such as Telegram and Discord.

In our analysis session, we can see that the sandbox detected a connection that triggered a Suricata rule. This suggests that the Meduza Stealer managed to capture and possibly exfiltrate sensitive information, such as usernames, passwords, or other authentication data.

Meduza in ANY.RUN sandbox Meduza detected by Suricata IDS in the ANY.RUN sandbox

After gathering the necessary data, Meduza compiles this information and uploads it to the attacker’s remote server. Its architecture enables it to evade detection by many antivirus solutions, making it particularly difficult for cybersecurity measures to recognize its presence.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Meduza Stealer distribution methods

Meduza Stealer is distributed through several methods, making it a versatile threat for attackers. Below are the primary ways in which Meduza Stealer spreads:

  • Infected email attachments: Phishing emails with malicious attachments trick victims into downloading the malware.
  • Malicious online advertisements: Meduza can be distributed via malvertising campaigns, where users clicking on seemingly legitimate ads are redirected to download the malware.
  • Social engineering: Attackers may use deceptive tactics to convince users to download the stealer, often by posing as legitimate sources.
  • Software cracks: The malware is often bundled with pirated software, tricking users into downloading Meduza while they believe they are obtaining legitimate applications.

Gathering threat intelligence on Meduza Stealer malware

To collect up-to-date intelligence on Meduza Stealer, use Threat Intelligence Lookup.

This service gives you access to a vast database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox.

With over 40 customizable search parameters, including IPs, domains, file names, and process artifacts, you can efficiently gather relevant data on threats like Meduza Stealer.

Meduza Suricatain ANY.RUN Search results for Meduza Stealer in Threat Intelligence Lookup

For example, you can search directly for the threat name or use related indicators like hash values or network connections. Submitting a query such as threatName:"Meduza" will generate a list of associated samples and sandbox results, giving you comprehensive insights into this malware’s behavior.

Request a 14-day free trial of Threat Intelligence Lookup along with ANY.RUN’s sandbox for detailed malware analysis.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Meduza Stealer is a dangerous piece of malware due to its extensive data-harvesting capabilities, including the ability to steal sensitive information from browsers, cryptocurrency wallets, and password managers. The malware’s stealth techniques make it difficult to detect, posing a serious threat to both individuals and businesses.

ANY.RUN offers a powerful solution for analyzing suspicious files and URLs in real time, enabling users to identify threats like Meduza Stealer before they can cause damage.

Sign up for a free ANY.RUN account today to analyze malware and find solutions to prevent potential breaches!

HAVE A LOOK AT

Caminho Loader screenshot
Caminho Loader
caminho caminholoader
Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms. Active since March 2025, it has delivered a variety of malware and infostealers to victims within multiple industries across South America, Africa, and Eastern Europe.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More