CopperStealer is a Windows malware family centered on browser credential and cookie theft, with additional downloader functionality and later cryptocurrency-focused extensions. Active since at least 2019, it has been used to steal saved browser credentials, session cookies, and account data from major online platforms, including social media, e-commerce, payment, and web service providers. A prominent objective has been the takeover and monetization of Facebook and Instagram business and advertiser accounts, using stolen cookies and credentials to obtain access tokens and enumerate associated assets. Later activity linked to the same ecosystem expanded into cryptocurrency theft through a malicious Chromium-based browser extension that harvested exchange account information, captured or created API keys, stole two-factor authentication codes through fake prompts, and initiated unauthorized transfers from victim wallets.
CopperStealer has commonly been distributed through fake crack, keygen, and warez sites, and has also been associated with pay-per-install distribution. In some campaigns it was bundled with other malware and potentially unwanted software, and its downloader capability enabled delivery of additional payloads after initial theft activity. Observed follow-on payloads have included SmokeLoader, and one delivery chain abused the legitimate Xunlei download manager to retrieve subsequent malware.
The malware incorporates multiple anti-analysis and resilience features, including debugger and virtualization checks, locale-based execution filtering, encrypted command-and-control traffic over HTTP, and an evolving domain generation scheme supplemented in later variants by backup infrastructure. It has searched multiple browsers for stored credentials and cookies, including Chromium-based browsers and Firefox. In cryptocurrency-focused deployments, the associated malicious extension modified Chromium browser settings to install itself persistently and targeted a broad range of Chromium-derived browsers.
CopperStealer is associated with the threat actor tracked as Water Orthrus, which has been linked to broader financially motivated activity involving ad injection, personal information theft, cryptocurrency theft, and later campaigns such as CopperStealth and CopperPhish. Multiple researchers have noted similarities between CopperStealer and other Chinese-linked malware used to monetize compromised online accounts, including overlap in tradecraft, delivery patterns, and infrastructure style. The family is best characterized as an infostealer with downloader functionality that evolved into a broader criminal toolkit for account compromise and financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2021, we have been tracking the activities of a threat actor we called Water Orthrus, which distributed CopperStealer malware via pay-per-install (PPI) networks. The threat actor has upgraded and modified the malware multiple times for different purposes, such as injecting network advertisements, acquiring personal information, and stealing cryptocurrency. We believe that they are associated with the threat campaign reported as “Scranos” in 2019.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The analyzed sample extracts a 7z archive named xldl.dat ... and then executes one of the extracted files (ThunderFW.exe ... ) via: C:\Users\<redacted>\AppData\Local\Temp\download\ThunderFW.exe ThunderFW "C:\Users\<redacted>\AppData\Local\Temp\download\MiniThunderPlatform.exe"
A newly installed extension is also added to the extension installation allow list located in the registry.
The analyzed sample also can drop and load a kernel driver ... The purpose of this driver is currently unknown.
This component uses the same cryptor described in previous posts in the first stage, followed by the second stage wherein the decrypted DLL is Ultimate Packer Executables-(UPX) packed... Both Javascript files are heavily obfuscated.
The analyzed sample created a mutex called "Global\exist_sign_install_r3" while other samples have created related mutexes
Device enumeration looking for indicators of virtualization
The malware does make use of several basic anti-analysis techniques to avoid running within researcher systems. IsDebuggerPresent() check GetSystemDefaultLCID() == 0x804 ... Window/class enumeration looking for common analysis tools ... Device enumeration looking for indicators of virtualization
A newly installed extension is also added to the extension installation allow list located in the registry.
The malware contains the ability to find and send saved browser passwords. The following Internet browsers are searched specifically for Facebook saved credentials: Chrome Edge Yandex Opera Firefox
In addition to the saved browser passwords, the malware uses stored cookies to retrieve a User Access Token from Facebook.
the routine responsible for stealing the 2FA passwords from the victims... The modal window has input boxes... they are concatenated into one “tfa” (2FA) variable and sent as a parameter of “createApi” message to the background script.
we found a malicious browser extension capable of creating and stealing API keys from infected machines... If successful, the background script then continues with extracting two API keys (API Key and API Secret) from the “API key details” form, saves them to Chromium’s local storage for later use, and exfiltrates them
Device enumeration looking for indicators of virtualization
The malware does make use of several basic anti-analysis techniques to avoid running within researcher systems. IsDebuggerPresent() check GetSystemDefaultLCID() == 0x804 ... Window/class enumeration looking for common analysis tools ... Device enumeration looking for indicators of virtualization
The first one is a GET request to http://<C&C server>/traffic/chrome... the data contains the domains of cryptocurrency-related websites based on the cookies found in the machine
Once the User Access Token is gathered, the malware requests several API endpoints for Facebook and Instagram to gather additional context, including a list of friends, any advertisement accounts configured for the user and a list of pages the user has been granted access
The first one is a GET request to http://<C&C server>/traffic/chrome ... The second query is a POST request to http:// <C&C server>/traffic/domain ... The result of this request is also exfiltrated to http://<C&C server>/traffic/step .
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware distributed via phishing to steal credit card information.
A malware family previously distributed by Water Orthrus via PPI networks, evolved across versions to inject advertisements, collect personal information, and steal cryptocurrency.
CopperStealer is described as malware distributed via fake crack/warez sites, often bundled with other malware in a dropper. In this campaign it installs a malicious Chromium-based browser extension that targets cryptocurrency users, steals or creates Coinbase API keys, captures 2FA codes, exfiltrates wallet/account data, and attempts to transfer 85% of victims’ crypto funds to attacker-controlled wallets.
A credential and cookie stealer focused on social media and online service accounts, especially Facebook and Instagram business/advertiser accounts. It steals saved browser passwords and cookies, retrieves Facebook access tokens and account context, exfiltrates victim data, and includes a downloader function to fetch and execute additional payloads via DGA-based C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.