Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Socelars

109
Global rank
145 infographic chevron month
Month rank
112 infographic chevron week
Week rank
0
IOCs

Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.

Stealer
Type
Unknown
Origin
1 December, 2019
First seen
7 September, 2026
Last seen

How to analyze Socelars with ANY.RUN

Type
Unknown
Origin
1 December, 2019
First seen
7 September, 2026
Last seen

IOCs

IP addresses
130.211.204.114
91.121.67.60
172.67.74.161
104.247.81.99
142.250.154.94
212.193.30.29
212.193.30.45
199.232.214.172
212.192.241.62
135.181.129.119
104.20.29.150
162.159.133.233
162.159.130.233
104.26.3.46
142.251.110.94
45.133.1.107
57.153.246.3
48.192.1.64
45.9.20.13
2.16.189.232
Hashes
97de47068327bb822b33c7106f9cbb489480901a6749513ef5c31d229dcaca87
e5a0ad2e37dde043a0dd4ad7634961ff3f0d70e87d2db49761eb4c1f468bb02f
f619737825736cb07fa257b49de1473d191f97bfc4865d1d463da4775107cb42
2b8b9dd101fc57f8d10ce4f074c0005df955634dbb7d9e49465f9054d66628a9
6913b6cc93ab1fb509ab7459d6158be6f1b03ab06d2ed41782b86838bd504c49
199b2760ea58e930c7f2f2a4291b0faae59abd9948a35e568eca5a16a40cacf8
2d8f31b9af7675e61537ccadf06a711972b65f87db0d478d118194afab5b8ac3
45ed5fbac043165057280feac2c2b8afcf9981b5c1b656aa4bf1c03cf3144d42
79549765b31c2d546a368b2a75378ff43a859345bb1b5a6263418829baa2d50e
03d498a0a514396d851a4da6106d21390781c64409dd3cfc67764f09d7909284
a86843475eb2d3128158cc781428ecc6ed86e1432ea18dcb74009c805bc15320
4feb70ee4d54dd933dfa3a8d0461dc428484489e8a34b905276a799e0bf9220f
0300e9ddb527990e8b59d06e9ccf3ec2bd92d3bbd0ef4fba69d6336e4195e82d
400800c461437e5e304ec4a597acc79436e522afd0acb7e32cc01ff26d3133dc
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c
9089a0c81374c15b534312cb302e661708616c3b4efdcfaee434d04e62615617
1043f9a9f3b1689e0ece9f83ef065114697f2e3ec87eef75b4ab56f9a7e0796f
117988c2bb069659ca52fba62553f835417935c05c13b4cc258c7c8caaaac7c3
a7de5177c68a64bd48b36d49e2853799f4ebcfa8e4761f7cc472f333dc5f65cf
b02fffaba9e664ff7840c82b102d6851ec0bb148cec462cef40999545309e599
Domains
ctldl.windowsupdate.com
c.pki.goog
pastebin.com
wfsdragon.ru
56.jpgamehome.com
iplogger.org
cdn.discordapp.com
google.com
client.wns.windows.com
yr.c.lencr.org
directorycart.com
futurepreneurs.eu
gcl-gb.biz
x1.c.lencr.org
login.live.com
go.microsoft.com
watson.events.data.microsoft.com
yr1.c.lencr.org
settings-win.data.microsoft.com
www.microsoft.com
URLs
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0e8028ac689bf8da
http://c.pki.goog/r/gsr1.crl
http://c.pki.goog/r/r4.crl
http://c.pki.goog/we1/btvd66z9uqy.crl
https://iplogger.org/143up7
https://iplogger.org/1brhn7
https://iplogger.org/1bthn7
https://pastebin.com/raw/a7dsg1te
http://wfsdragon.ru/api/setstats.php
https://cdn.discordapp.com/attachments/910281572803047425/910423656306446387/pctool.exe
http://ip-api.com/json/
https://cdn.discordapp.com/attachments/900442917435473960/900698311521103882/pctool.exe
https://iplogger.org/1a2jd7
http://gcl-gb.biz/stats/1.php?pub=/mixone&badparam=nope
https://iplogger.org/1a3jd7
https://watson.events.data.microsoft.com/telemetry.request
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://gcl-gb.biz/check.php?pub=mixone
Last Seen at
Last Seen at

Recent blog posts

post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 837
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 3133
comments 0
post image
Release Notes: Faster TI Investigations, Fres...
watchers 7591
comments 0

Socelars: The Stealer That Turns Business Accounts into Cash

Key Takeaways

  • Built for ad account takeover: Socelars is explicitly associated with stealing data tied to Facebook Ads Manager operations, putting marketing budgets, brand pages, and business accounts at risk.

  • Cookie theft enables fast account abuse: Reported behavior includes stealing session cookies (Facebook and Amazon mentioned in public reporting), which can allow attackers to access accounts immediately without waiting for password resets.

  • Social-engineering friendly delivery: Campaigns have used a fake PDF reader lure to get users to install the malware, taking advantage of routine workplace behavior around “helper” tools.

  • Spyware/stealer family: Security vendors classify Socelars as a spyware/credential-stealing threat, built for quiet data theft rather than loud disruption.

  • ANY.RUN’s Threat Intelligence Lookup helps SOCs quickly understand Socelars activity at scale and uncover relationships between related samples and infrastructure.

threatName:"socelars".

Socelars overview in TI Lookup

Socelars overview in TI Lookup: targeted industries and countries, IOCs, samples

  • ANY.RUN’s Interactive Sandbox lets teams safely observe Socelars’ behavior and extract actionable indicators in real time.

View analysis

Socelars malware analysis in Interactive Sandbox Socelars stealer detected by ANY.RUN sandbox

What is Socelars Malware?

Socelars is an information-stealing malware family designed to harvest authenticated session data, system identifiers, and other artifacts that enable rapid account takeover and financial abuse.

Rather than disrupting systems immediately, it focuses on quietly collecting the access attackers need to operate inside trusted business services and logged-in environments.

Public reporting links Socelars activity to the theft of session cookies associated with platforms such as Facebook and Amazon, which can allow attackers to access accounts without waiting for password resets or triggering obvious security alerts.

This makes the threat especially dangerous for organizations that rely on advertising platforms, e-commerce accounts, or cloud-based business tools, where stolen sessions can be monetized quickly.

From a technical perspective, Socelars combines:

  • System reconnaissance to profile the infected environment
  • Privilege escalation techniques, including UAC bypass through COM auto-elevation
  • Stealthy data collection targeting browser-stored authentication artifacts
  • Minimal visible impact, allowing abuse to occur before detection

As the malware’s primary goal is immediate operational access rather than destruction, traditional defenses that focus on ransomware-style behavior may detect the incident too late.

In practice, Socelars turns a single unnoticed infection into a pathway for account compromise, financial loss, and compliance exposure, making early behavioral detection and threat-intelligence visibility critical for effective defense.

How Socelars Threatens Businesses and Organizations

Socelars is dangerous not because it disrupts systems immediately, but because it quietly targets the accounts and sessions that drive revenue and operations.

Instead of triggering visible alarms, the malware focuses on stealing authenticated browser data and business platform access, allowing attackers to act as legitimate users while remaining unnoticed.

Key business risks include:

  • Direct financial loss through ad account abuse: Access to Facebook Ads Manager sessions enables attackers to launch fraudulent campaigns, drain advertising budgets, or resell compromised accounts on underground markets.

  • Account takeover without traditional credential theft: By extracting active session cookies, attackers may bypass password resets and, in some cases, multi-factor authentication flows, gaining immediate control over business services.

  • Reputational and customer-trust damage: Compromised advertising or brand pages can be used to distribute scams, malicious links, or misleading promotions that impact customer confidence and brand integrity.

  • Compliance and data-protection exposure: Unauthorized access to business platforms and stored user data may trigger regulatory obligations, breach notifications, and potential financial penalties.

  • Hidden dwell time before discovery: Because Socelars operates quietly in the background, attackers may maintain access long enough to monetize accounts or expand compromise before defenders notice suspicious activity.

This means a single infected workstation can escalate into a multi-department business incident affecting marketing, finance, legal, and security teams simultaneously.

Victimology: Vulnerable Industries and Sectors

Socelars targets business accounts and browser sessions, not infrastructure, so risk is the highest where authenticated access maps directly to money.

Most exposed sectors include:

  • Marketing and advertising-driven companies: Heavy use of Facebook Ads Manager creates direct budget and account-takeover risk.

  • Agencies managing client ad accounts: One infected workstation can impact multiple customers at once.

  • E-commerce and consumer brands: Ad abuse can quickly translate into lost spend, fraud, and customer trust damage.

  • SMEs: More likely to fall for fake utility lures (such as PDF tools) due to lighter controls and training.

In practice, exposure depends less on industry and more on how much the organization relies on long-lived browser sessions for business-critical platforms.

How Can Businesses Proactively Protect Against Socelars

ANY.RUN’s Threat Intelligence Feeds deliver real-time, actionable indicators derived from sandbox detonations and global community submissions.

For Socelars, these feeds surface emerging distribution artifacts, related samples, and infrastructure linked to session-stealing activity, enabling automated detection and blocking across firewalls, EDR, and SIEM platforms.

This allows organizations to identify compromise before stolen sessions are abused, shorten attacker dwell time, and prevent follow-on fraud or account takeover, which is critical for threats designed to monetize access quickly rather than disrupt systems immediately.

Business Impact:

  • Reduced Mean Time to Detect (MTTD): Fresh indicators help teams identify Socelars activity within minutes, limiting the window for silent session theft.

  • Prevention of Account Abuse and Financial Loss: Blocking known artifacts and related infrastructure reduces the chance of fraudulent ad spending, unauthorized campaigns, and account resale.

  • Protection of Brand Trust and Compliance Posture: Early detection lowers the risk of customer-facing scams, data exposure, and regulatory consequences tied to compromised business accounts.

  • Stronger Security ROI Through Shared Intelligence: Leveraging threat intelligence contributed by 15,000+ organizations improves detection coverage without requiring proportional investment in new tooling or staffing.

TI Feeds: data & capabilities TI Feeds: data & capabilities

Infection Vectors and Propagation Methods

Socelars is primarily distributed through social-engineering techniques designed to appear routine and trustworthy rather than overtly malicious.

Public reporting links campaigns to fake software utilities, including installers presented as legitimate PDF readers or similar everyday tools, which encourages users to execute the malware without suspicion.

These delivery methods rely on common workplace behavior: downloading quick-fix utilities, opening attachments tied to business activity, or installing software outside approved channels.

Because the initial file often looks harmless, traditional security controls may not flag the threat before execution.

Propagation Mechanism

After execution on a victim system, Socelars focuses on local data collection and session extraction rather than noisy self-spreading behavior.

Typical post-infection activity includes:

  • Accessing browser storage and session cookies tied to business services;

  • Collecting authentication data that enables immediate account takeover or fraud;

  • Preparing stolen information for exfiltration and attacker monetization.

This approach allows attackers to move directly from a single user action to business-level impact, without requiring lateral movement or complex network propagation.

In practice, Socelars spreads less through automated worm-like behavior and more through repeatable social-engineering campaigns, making user interaction and early detection the critical defensive boundary.

How Socelars Functions

Socelars is designed to quietly extract high-value authentication data from an infected Windows system rather than cause immediate disruption. Its goal is to obtain information that allows attackers to access business-critical online services, especially advertising platforms and other authenticated web applications, without triggering obvious alerts.

Stage 1: Execution and Environment Preparation

After a victim runs the disguised installer or utility, Socelars begins operating in the background with minimal visible activity.

At this stage, the malware prepares the environment for data collection, ensuring it can access local browser storage, session artifacts, and user profile data without interrupting normal system use.

Stage 2: Session and Credential Data Collection

The core capability of Socelars is harvesting information that provides ready-to-use access rather than just raw credentials.

This includes:

  • Active browser session cookies that may allow attackers to bypass login prompts

  • Stored authentication data tied to business platforms such as advertising or e-commerce services

  • Additional local information useful for account takeover or monetization

As session data can remain valid even after passwords change, this stage enables immediate unauthorized access and rapid financial abuse.

Stage 3: Data Exfiltration and Monetization

Once sensitive data is collected, Socelars prepares it for exfiltration to attacker-controlled infrastructure.

The stolen access can then be used to:

  • Launch fraudulent advertising campaigns or drain marketing budgets

  • Resell compromised business accounts on underground markets

  • Expand compromise into related services or customer-facing assets

Unlike ransomware, which reveals itself through visible disruption, Socelars completes its objective silently, allowing attackers to profit before defenders detect the intrusion.

Sandbox Analysis of a Socelars Sample

To understand how Socelars behaves in a real environment, analysts can detonate a suspected sample inside ANY.RUN’s Interactive Sandbox, where execution unfolds safely and every action is recorded in real time.

View analysis session with Socelars

Socelars detected by ANY.RUN Sandbox Socelars stealer detected by ANY.RUN sandbox

Immediately after execution, the malware begins system reconnaissance on the infected host. It collects the computer name, extracts the Machine GUID from the registry, checks installed system languages, reads Internet Settings parameters, and inspects system certificate configuration.

System reconnaissance by Socelars stealer System reconnaissance by Socelars stealer

The next stage involves a User Account Control (UAC) bypass. Socelars launches dllhost.exe with the parameter /Processid:{CLSID}, where the CLSID corresponds to the ICMLuaUtil interface from cmlua.dll, a component that allows auto-elevated privilege execution.

Through this COM object, the malware invokes the **ShellExec method to run its payload with elevated rights.

Socelars bypassing user account control detected in ANY.RUN sandbox Socelars bypassing user account control, detected in ANY.RUN sandbox

After successful privilege escalation, the sample creates a mutex named “patatoes”, a distinctive artifact associated with this Socelars variant.

The interactive sandbox detected Socelar’s mutex The Interactive Sandbox detected Socelar’s mutex

The malware then contacts the iplogger[.]org service. In this context, the public IP-logging service acts as a proxy layer, recording the victim’s IP address, User-Agent, timestamp, and geographic location for the attacker before transparently redirecting the request further, potentially toward a command-and-control server or the next attack stage.

At this point, all analyzed samples were observed to terminate intentionally with a crash, preventing further visible execution while preserving the attacker’s collected reconnaissance and telemetry.

Intentional application crash to prevent visible execution Intentional application crash to prevent visible execution

Gathering Threat Intelligence on Socelars Stealer

ANY.RUN’s Threat Intelligence Lookup provides critical capabilities for detecting, investigating, and responding to Socelars activity across environments.

Rapid Indicator Validation and Context Enrichment

When security alerts surface potential Socelars-related artifacts, such as suspicious installers, file hashes, domains, or browser-data access behavior, SOC analysts can query TI Lookup to immediately determine whether those indicators are linked to known session-stealing campaigns.

TI Lookup enriches raw indicators with:

  • malware family classification,
  • related samples and execution history,
  • behavioral context tied to account-takeover activity

This turns isolated alerts into actionable intelligence within seconds, enabling faster containment of threats that monetize access quickly.

Direct Access to Confirmed Behavioral Analysis

TI Lookup connects indicators to interactive sandbox sessions where Socelars attack chains have already been executed and recorded.

Instead of re-analyzing suspicious files from scratch, teams can:

  • Observe how the malware accesses browser storage and session data;
  • Review outbound communication and potential exfiltration patterns;
  • Extract high-confidence indicators for environment-wide blocking.

Start exploring Socelar’s activity using a threat-name search:

threatName:"socelars".

Fresh Socelar’s sandbox analyses found via TI Lookup Fresh Socelar’s sandbox analyses found via TI Lookup

This immediate visibility shortens investigation time and accelerates response decisions.

Multi-Dimensional Event Correlation

With 40+ searchable parameters, including process activity, command lines, file paths, registry interaction, and network indicators, analysts can investigate Socelars infections from multiple angles.

For example, correlating browser-data access patterns or suspicious installer execution across submissions can reveal:

  • Repeated distribution techniques,
  • Shared infrastructure,
  • Evolving campaign behavior.

This allows defenders to move from single-incident response to campaign-level understanding.

Detection Engineering and Rule Validation

TI Lookup supports YARA-based searching and validation, allowing security teams to test custom detection logic against a large corpus of analyzed malware.

For Socelars, this helps teams:

  • Identify unique data-collection or execution traits;
  • Validate detection rules against real samples;
  • Reduce false positives before deployment in production controls.

Proactive Threat Hunting

Beyond reactive investigation, analysts can use TI Lookup to hunt for hidden Socelars activity that may have bypassed initial alerts, particularly important for malware focused on quiet session theft rather than visible disruption.

Operational Value for SOCs and MSSPs

Combining sandbox intelligence with large-scale threat correlation delivers measurable outcomes:

  • Reduced Mean Time to Respond (MTTR),
  • Lower false-positive investigation overhead,
  • Broader detection coverage across environments,
  • Improved analyst efficiency and workload balance,
  • Optimized security cost through shared intelligence.

Conclusion

Socelars is dangerous because it targets business access instead of systems, stealing sessions and account data that attackers can monetize quickly, often before teams realize anything is wrong. The fastest way to reduce impact is to confirm behavior early and widen visibility beyond a single alert with threat intelligence.

Try TI Lookup to find related Socelars activity, validate indicators in seconds, and understand campaign scope fast: just sign up to ANY.RUN.

HAVE A LOOK AT

DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More