Ficker Stealer is a Rust-based Windows information stealer first observed in 2020 and marketed as malware-as-a-service on Russian-speaking cybercriminal forums. It harvests browser credentials and information, payment-card data, cryptocurrency-wallet data, and sensitive files, captures screenshots, and exfiltrates collected data directly to operator-controlled infrastructure. It can also download and execute additional payloads after command-and-control communication is established. Ficker Stealer employs obfuscation, virtual-machine detection, and geofencing that avoids execution in several CIS and nearby countries. Observed delivery includes trojanized download links, compromised websites, and phishing or spam campaigns using macro-enabled Excel attachments; these campaigns have used Hancitor to deploy the payload through process hollowing. DocuSign-themed lures have also been associated with its delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
« Des mécanismes d’obfuscation et d’évasion sont employés afin de limiter sa détection »
"injects the final payload using a technique called process hollowing"
« il collecte des informations relatives au système, à la configuration de la machine et au contexte utilisateur »
"anti-analysis checks that prevent it from running on virtualized environments"
Follow the TCP stream with port 49807 as the TCP source port. This should show approximately 1.16 MB of data. The majority of it appears encoded or otherwise obfuscated.
"Hancitor will often reach out to its command-and-control (C2) infrastructure to receive a malicious URL"
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Insights Report Q4-2020 Agent Tesla BitRAT ComodoSec Dridex Emotet Ficker Stealer Formbook Zloader
Mentioned only as a comparison point for BlackGuard's potential future impact.
Information-stealing malware referenced as an example of a Rust-written malware strain.
Credential/data stealing malware delivered as a secondary payload by Hancitor in this intrusion; a successful outbound connection from it was not observed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.