STEALDEAL is an information-stealing malware and browser-data stealer. Reported capabilities include theft of internet browsing data, browser cookies, and passwords stored in web browsers. Trend Micro also noted it is detected as TrojanSpy.Win64.STEALDEAL and is also known as SneakyStealer. Observed browser targets include Google Chrome, Microsoft Edge, Mozilla Firefox, Chromium, Chrome Beta, and Yandex Browser, with stolen data stored at %PUBLIC%\Libraries\BrowserData\Result in the described campaign. In one CERT-UA-reported phishing operation targeting users of Ukraine’s DELTA situational awareness program, victims received messages from a compromised Ukrainian Ministry of Defense email account claiming DELTA certificates needed updating. The lure led to a PDF and then a ZIP archive containing a signed executable, which simulated certificate installation while dropping VMProtect-protected DLLs; CERT-UA identified procsys.dll as STEALDEAL. Separately, Trend Micro described STEALDEAL as an auxiliary component deployed by the RomCom backdoor used by Void Rabisu / Tropical Scorpius in campaigns affecting Ukrainian government, military, and critical infrastructure as well as European and US entities connected to support for Ukraine. In that reporting, procsys.dll was specifically described as a STEALDEAL browser cookie stealer. High-confidence associated artifacts from the provided content include the filename procsys.dll and the output path %PUBLIC%\Libraries\BrowserData\Result.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"procsys.dll – a stealer known as STEALDEAL to retrieve browser cookies..."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“A compromised Ukrainian Ministry of Defense email account was found sending phishing emails and instant messages… with fake warnings that users need to update the 'Delta' certificates… The malicious email contains a PDF… which includes links to download a ZIP archive…”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential/cookie and browsing-data stealer delivered via RomCom C2; targets multiple browsers (Chrome/Edge/Firefox/Chromium/Chrome Beta/Yandex) and collects mail client info, staging output locally for later exfiltration via RomCom command-and-control.
Information-stealing malware focused on harvesting browser data, including stored credentials/passwords and browsing information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.