Raven Stealer is a lightweight information-stealing malware family developed primarily in Delphi and C++ and focused on harvesting sensitive data from Windows systems. It is designed to target Chromium-based browsers, including major variants such as Chrome and Edge-family browsers, and to extract stored credentials, cookies, payment-card data, and autofill information. Reported functionality also includes theft of data from cryptocurrency wallets, gaming platforms, VPN clients, and messaging applications.
The malware uses a builder-and-payload architecture in which a Delphi-based builder generates a C++ stealer payload. Operationally, it emphasizes stealth and evasion. Documented behaviors include hiding its user interface, storing operator Telegram configuration in embedded resources, decrypting components in memory, and using reflective process hollowing with direct syscalls to inject into legitimate browser processes. It has also been reported to relaunch browsers in suspended and headless states to facilitate access to protected browser data and bypass Chromium App-Bound Encryption through in-memory techniques.
Collected data is staged locally in a structured directory hierarchy, compressed into an archive, and exfiltrated through Telegram using the Bot API, specifically document-upload functionality. Distribution has been associated with GitHub-hosted repositories and promotion through Telegram channels. The malware ecosystem has been linked to the ZeroTrace Team, which has also been associated with Octalyn Stealer. Raven Stealer fits the current trend of commodity and semi-private infostealers that combine browser credential theft, cryptocurrency targeting, and Telegram-based exfiltration with increasingly mature defense-evasion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Raven Stealer is a modern, lightweight, information-stealing malware developed primarily in Delphi and C++, designed to extract sensitive data from victim machines with minimal user interaction and high operational stealth.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Unlike Python-based stealers, Raven’s compiled binaries are packed using UPX, reducing their size and improving evasion against static detection mechanisms.
MITRE ATTACK FRAMEWORK Tactic ID Technique Name ... T1027.005 Indicator Removal from Tools
Several imported functions—such as Process32NextW, GetCurrentProcessId, and CreateProcessW—along with the unusually large size of certain resource sections, indicate that the malware is designed to perform DLL injection into legitimate processes.
This untouched, suspended process becomes the target for reflective process hollowing, allowing the injected code to run under the browser’s identity while avoiding common detection mechanisms.
MITRE ATTACK FRAMEWORK Tactic ID Technique Name ... T1497 Virtualization/Sandbox Evasion
MITRE ATTACK FRAMEWORK Tactic ID Technique Name ... T1542 Pre-OS Boot T1542.003 Bootkit
Several imported functions—such as Process32NextW, GetCurrentProcessId, and CreateProcessW—along with the unusually large size of certain resource sections, indicate that the malware is designed to perform DLL injection into legitimate processes.
All stolen credentials and system information are stored in an organized directory structure within the %Local%\ RavenStealer folder.
The malware performs system-wide enumeration to locate stored credentials on the infected machine.
MITRE ATTACK FRAMEWORK Tactic ID Technique Name ... T1497 Virtualization/Sandbox Evasion
After extracting the data, the malware collects information from various sources such as cryptocurrency wallets, saved passwords, browser cookies, gaming platforms, VPN clients, and instant messaging services.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer referenced for comparison because it uses a similar Telegram sendDocument ZIP exfiltration pattern.
Raven Stealer is a lightweight infostealer that archives stolen data and exfiltrates it via Telegram's API, typically using PowerShell and curl.
Infostealer malware targeting Chromium-based browsers to steal credentials and sensitive data.
Information stealer facilitating credential theft, browser data harvesting, and real-time data exfiltration via Telegram bot integration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.