Ficker Stealer is a Windows information-stealing malware family written in Rust and marketed in cybercriminal underground communities as a malware-as-a-service offering. First observed in 2020, it is designed to harvest sensitive data from infected systems, including login credentials, browser information, payment card data, cryptocurrency wallet data, and selected files. It also supports screen capture and can function as a downloader to retrieve and execute additional payloads after establishing command-and-control communications.
The malware has been associated with delivery through trojanized web links, compromised websites, and phishing-driven campaigns. Observed infection chains include macro-enabled Microsoft Office lures that deploy Hancitor, which then delivers Ficker Stealer as a follow-on payload. DocuSign-themed lures and other scam-style landing pages offering pirated or free access to paid services have also been linked to its distribution.
Ficker Stealer is notable for heavy obfuscation and anti-analysis measures. Reported protections include checks intended to prevent execution in virtualized environments and geofencing logic that avoids running on systems located in several post-Soviet states. Unlike some stealers that stage collected data locally before transmission, Ficker Stealer has been described as exfiltrating stolen information directly to operator-controlled infrastructure. It has also appeared in broader crimeware bundles and post-compromise payload sets alongside Hancitor and Cobalt Strike, reflecting its role as a commodity stealer used in multi-stage intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Follow the TCP stream with port 49807 as the TCP source port. This should show approximately 1.16 MB of data. The majority of it appears encoded or otherwise obfuscated.
"Hancitor will often reach out to its command-and-control (C2) infrastructure to receive a malicious URL"
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Insights Report Q4-2020 Agent Tesla BitRAT ComodoSec Dridex Emotet Ficker Stealer Formbook Zloader
Mentioned only as a comparison point for BlackGuard's potential future impact.
Information-stealing malware referenced as an example of a Rust-written malware strain.
Credential/data stealing malware delivered as a secondary payload by Hancitor in this intrusion; a successful outbound connection from it was not observed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.