0bj3ctivity Stealer is an information-stealing malware family observed in phishing campaigns. The provided content states that phishing emails using purchase-order lures have distributed 0bj3ctivity Stealer via JavaScript files, and that operators have also hidden the malware in images using steganographic delivery. The content further notes that the malware has previously been propagated via Ande Loader.
Based on the ATT&CK and detection references in the content, 0bj3ctivity Stealer is associated with behaviors common to stealers and related malware families, including ingress tool transfer or downloading additional payloads (T1105), browser credential theft (T1555.003), and command-and-control over web protocols/HTTP (T1071.001). Splunk analytic-story associations in the content also link it to suspicious PowerShell activity, reflective .NET loading in memory via PowerShell, suspicious child processes spawned by wscript.exe or cscript.exe, scheduled-task-based execution or persistence, and victim network reconnaissance through IP-check or geolocation web services. These references indicate likely Windows-focused execution and persistence tradecraft, but the content does not provide a definitive malware-specific procedure breakdown beyond the ATT&CK associations.
The content does not attribute 0bj3ctivity Stealer to a specific threat actor with high confidence. It does indicate global phishing impact and places the malware alongside other stealer and RAT families in Splunk analytic stories and related detections. No malware-specific indicators of compromise such as hashes, domains, mutexes, registry keys, or file paths are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer malware family referenced as an associated analytic story.
Associated Analytic Story 0bj3ctivity Stealer
0bj3ctivity Stealer is referenced as a named stealer malware family associated with the analytic story tied to suspicious scheduled task activity.
Stealer malware referenced as an associated analytic story.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.