Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Meduza Stealer

119
Global rank
142 infographic chevron month
Month rank
151 infographic chevron week
Week rank
0
IOCs

Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.

Stealer
Type
Unknown
Origin
1 June, 2023
First seen
30 January, 2026
Last seen

How to analyze Meduza Stealer with ANY.RUN

Type
Unknown
Origin
1 June, 2023
First seen
30 January, 2026
Last seen

IOCs

IP addresses
188.114.97.3
188.114.96.5
172.67.152.71
38.91.107.229
38.91.107.2
14.0.37.128
46.34.51.181
77.239.121.89
172.67.209.38
172.67.213.74
172.67.199.82
172.67.167.216
172.67.148.242
104.21.20.77
45.91.94.210
104.21.85.251
104.21.4.14
104.21.55.141
104.21.34.31
104.21.21.153
Domains
hotsocks.ws
hotsocks.biz
hector.su
avscan.net
binsoficial666.activo.mx
faceless.cc
bclub.cm
b1ackstash.cc
c0nnect.pro
ghostsocks.net
xleet.pw
stashpatrick.io
vn5socks.net
spamir.fr
alarti.ru
openmailertrack.com
usps-mypackage.com
royalescort.net
tracking-usps.com
vpn567288128.softether.net
Last Seen at

Recent blog posts

post image
How Threat Intelligence Helps Protect Financi...
watchers 380
comments 0
post image
Release Notes: Workflow Improvements, MISP In...
watchers 2141
comments 0
post image
Enterprise Phishing: How Attackers Abuse Trus...
watchers 4192
comments 0

What is Meduza Stealer?

Meduza Stealer is a sophisticated piece of information-stealing malware designed to target a wide range of sensitive data on infected systems. Its execution process is systematic, involving several key stages that ensure efficient data collection while evading detection.

First discovered in 2023, it has quickly become notorious for its wide-reaching capabilities, targeting over 100 web browsers and 107 cryptocurrency wallets. Meduza can collect data such as login credentials, browser history, bookmarks, autocomplete fields, and even sensitive information stored in applications like Telegram, Discord, and Steam.

It has an advanced structure that allows it to operate stealthily, using several techniques to evade detection by antivirus programs and other security measures.

Meduza Stealer is distributed through a Malware-as-a-Service (MaaS) model on underground forums and Telegram, making it accessible to cybercriminals with varying technical skill levels. For a subscription fee, attackers can customize Meduza Stealer to suit their needs.

Once it infects a system, the malware establishes communication with a Command and Control (C2) server to upload stolen data. A web panel allows attackers to view the exfiltrated information, which can include operating system details, IP addresses, and the nature of the stolen data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Meduza Stealer technical details

Meduza Stealer collects a wide variety of sensitive data, including login credentials, browsing history, cookies, and cryptocurrency wallets.

Here are the main technical functionalities of this malware:

  • Establishes a connection with a command-and-control server to exfiltrate stolen data.
  • Alters system registry keys to ensure persistence after rebooting the infected machine.
  • Uses encryption techniques to protect the stolen data during transmission to evade detection.
  • Doesn’t employ obfuscation techniques, making it harder to identify and trace.
  • Attackers can customize payloads via a web panel, adjusting the malware for specific campaigns.
  • Focuses on stealing data from browsers, cryptocurrency wallets, and messaging platforms like Telegram and Discord.
  • Extracts data from various password management tools, giving attackers access to stored credentials.
  • Utilizes anti-debugging techniques to avoid detection in sandbox environments.
  • Operates silently in the background to avoid raising suspicion from the victim.

Meduza Stealer performs geolocation checks on the infected system using the victim's IP address. If the location matches a region in its exclusion list, the malware halts its operations, thus avoiding detection and action in certain regions.

This malware can be delivered via malicious files like .exe, .doc, and .zip attachments, typically spread through phishing emails and malicious links.

Meduza stealer execution process

To see how Meduza stealer operates, let’s upload its sample to the ANY.RUN sandbox.

Upon infiltrating a system, Meduza first conducts a geolocation check using the victim's IP address. If the location matches an entry on its predefined exclusion list, the malware immediately halts its operations. If the check is passed, Meduza attempts to connect to its Command and Control (C2) server, which is one of the most crucial steps.

Meduza in ANY.RUN sandbox Process graph of Meduza Stealer inside ANY.RUN’s sandbox

If the server is unreachable, the malware terminates its process. Unlike many other stealers that delay contacting their C2 servers until after data collection, Meduza establishes this connection early in its execution.

Once connected to the C2 server, Meduza begins collecting extensive information from the infected machine, including:

  • System information: Details about the operating system and hardware.
  • Browser data: Login credentials, browsing history, cookies, and bookmarks from targeted browsers.
  • Password managers: Data from various password management applications.
  • Cryptocurrency wallets: Information from supported cryptocurrency wallet extensions.
  • Installed applications: Information about installed games and desktop applications such as Telegram and Discord.

In our analysis session, we can see that the sandbox detected a connection that triggered a Suricata rule. This suggests that the Meduza Stealer managed to capture and possibly exfiltrate sensitive information, such as usernames, passwords, or other authentication data.

Meduza in ANY.RUN sandbox Meduza detected by Suricata IDS in the ANY.RUN sandbox

After gathering the necessary data, Meduza compiles this information and uploads it to the attacker’s remote server. Its architecture enables it to evade detection by many antivirus solutions, making it particularly difficult for cybersecurity measures to recognize its presence.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Meduza Stealer distribution methods

Meduza Stealer is distributed through several methods, making it a versatile threat for attackers. Below are the primary ways in which Meduza Stealer spreads:

  • Infected email attachments: Phishing emails with malicious attachments trick victims into downloading the malware.
  • Malicious online advertisements: Meduza can be distributed via malvertising campaigns, where users clicking on seemingly legitimate ads are redirected to download the malware.
  • Social engineering: Attackers may use deceptive tactics to convince users to download the stealer, often by posing as legitimate sources.
  • Software cracks: The malware is often bundled with pirated software, tricking users into downloading Meduza while they believe they are obtaining legitimate applications.

Gathering threat intelligence on Meduza Stealer malware

To collect up-to-date intelligence on Meduza Stealer, use Threat Intelligence Lookup.

This service gives you access to a vast database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox.

With over 40 customizable search parameters, including IPs, domains, file names, and process artifacts, you can efficiently gather relevant data on threats like Meduza Stealer.

Meduza Suricatain ANY.RUN Search results for Meduza Stealer in Threat Intelligence Lookup

For example, you can search directly for the threat name or use related indicators like hash values or network connections. Submitting a query such as threatName:"Meduza" will generate a list of associated samples and sandbox results, giving you comprehensive insights into this malware’s behavior.

Request a 14-day free trial of Threat Intelligence Lookup along with ANY.RUN’s sandbox for detailed malware analysis.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Meduza Stealer is a dangerous piece of malware due to its extensive data-harvesting capabilities, including the ability to steal sensitive information from browsers, cryptocurrency wallets, and password managers. The malware’s stealth techniques make it difficult to detect, posing a serious threat to both individuals and businesses.

ANY.RUN offers a powerful solution for analyzing suspicious files and URLs in real time, enabling users to identify threats like Meduza Stealer before they can cause damage.

Sign up for a free ANY.RUN account today to analyze malware and find solutions to prevent potential breaches!

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More