EDDIESTEALER is a Rust-based commodity infostealer targeting Windows systems. It is distributed through ClickFix fake CAPTCHA campaigns on compromised or attacker-controlled websites, which manipulate victims into pasting and executing a malicious PowerShell command. The execution chain downloads a concealed JavaScript loader that retrieves and runs the stealer.
The malware uses XOR-encrypted strings, dynamic Windows API resolution, a per-sample mutex, and a physical-memory check that can terminate and remove the payload on low-memory systems. It obtains an AES-encrypted, task-based configuration from command-and-control infrastructure and exfiltrates encrypted host information and collected data through task-specific HTTP requests. Later variants collect expanded host profiling information and may receive no collection tasks when server-side checks identify suspected analysis environments.
EDDIESTEALER collects browser databases and extension data from Chromium- and Firefox-based browsers, including browsing history, bookmarks, cookies, autofill data, and saved credentials. It targets cryptocurrency wallets, password managers, FTP-client configurations, and Telegram Desktop data. It also implements Rust versions of Chromium credential-theft techniques to circumvent Chromium application-bound encryption. For Chrome Password Manager theft, it can launch Chrome with remote debugging enabled, cause credentials to be loaded by the browser, and scrape plaintext credentials from browser-process memory. No threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The copied PowerShell command silently downloads a second-stage payload, gverify.js, from an attacker-controlled domain.
The malware executes gverify.js using cscript in a hidden window; the script fetches the EDDIESTEALER executable.
EDDIESTEALER encrypts most strings via a simple XOR cipher, and the JavaScript payloads are obfuscated.
EDDIESTEALER decrypts target module and function names, dynamically loads modules, and uses a custom GetProcAddress implementation to resolve APIs.
The second-stage configuration data is AES CBC encrypted and Base64 encoded... Following the same data format... initial host information is AES-encrypted
EDDIESTEALER deletes itself through NTFS Alternate Data Streams renaming, then sets FILE_DISPOSITION_INFO.DeleteFile to delete on handle close.
For this particular sample... exfiltration targets: ... Browsers ... Password managers ... In order to get all entries of Chrome’s Password Manager, EDDIESTEALER begins its credential theft routine...
More recent samples collect running-process information; Chromium-specific theft identifies the browser network-service child process.
The malware profiles the executable location, locale, username, physical memory, OS version, and, in newer variants, GPU details, CPU information, and core count.
The malware retrieves configuration through HTTP GET and sends host information and stolen data through HTTP POST; it primarily relies on HTTP rather than HTTPS.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
Rust-based infostealer delivered via ClickFix fake CAPTCHA pages; steals sensitive browser data and is noted for bypassing Chrome App-Bound Encryption.
An infostealer profiled as a notable novel discovery by Elastic Security Labs.
An infostealer referenced as another malware family deployed via ClickFix social engineering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.