DeerStealer, also known as XFiles Spyware, is a malware-as-a-service infostealer operated in the cybercrime ecosystem and sold on Telegram-based forums. It is commonly assessed as an affiliate-driven criminal operation rather than a nation-state actor. DeerStealer is designed to steal credentials and other sensitive data from compromised Windows systems, with collection focused on browser-stored passwords, cookies, autofill data, payment-card data, browsing history, cryptocurrency wallets, browser extensions, messaging-session artifacts, VPN configurations, and FTP client credentials. Reported targeting includes more than 50 browsers, hundreds of browser extensions, and numerous cryptocurrency wallets. Operationally, DeerStealer has been distributed through social-engineering lures including fake software updates and deceptive installer bundles, and has been observed loaded through HijackLoader and through weaponized installer components that decrypt and execute the payload in memory. Campaigns have used signed or masqueraded binaries, decoy legitimate software, and staged multi-component loaders to reduce suspicion and evade detection. DeerStealer supports persistence through user-run startup mechanisms and scheduled tasks. Beyond credential theft, DeerStealer includes surveillance and post-compromise capabilities such as keylogging and a hidden VNC component for live desktop monitoring. It stages stolen data locally before exfiltration and has used encrypted HTTPS-based exfiltration through proxy infrastructure. Telegram has also been used in DeerStealer operations for execution notifications and related operational messaging. The actor or ecosystem behind DeerStealer is financially motivated and operates under a subscription-based MaaS model with affiliates likely responsible for individual delivery campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-Service infostealer platform used to steal browser credentials, cookies, crypto wallets, messaging sessions, and other sensitive data; observed here with hidden VNC, live keylogging, persistence, and encrypted exfiltration.
Malware-as-a-Service infostealer operation distributed via likely malvertising, using a WiX installer bundle and decoy software to steal browser credentials, crypto wallets, messaging sessions, VPN/FTP configs, screenshots, clipboard data, and to enable hidden VNC and keylogging.
DeerStealer is a multi-stage infostealer distributed via fake browser update campaigns, using Telegram for execution notifications and exfiltration of sensitive data.
Infostealer malware operation focused on stealing sensitive information from infected systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.