Stealer One
Stealer One is a credential-stealing malware family associated in the provided content with FIN6. It has been used by FIN6 to steal credentials from web browsers as well as from e-mail and file transfer utilities, including FTP. The available content specifically characterizes it as a credential stealer targeting stored account data in those application categories. No additional high-confidence details on infection vector, platform scope, industries targeted, or specific indicators of compromise are provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN6 has used the Stealer One credential stealer to target web browsers.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Credential Access
2 techniques"Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles." / "Mimikatz ... acquire information about credentials ... including from the credential vault and DPAPI." / "Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook."
The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential stealer used to target email and file transfer utilities including FTP.
Credential stealer used to target web browsers.
Credential stealer used to harvest credentials from email and file transfer utilities (including FTP).
Credential stealer used to target and extract credentials from web browsers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.