Arkei is a Windows information-stealing malware family that emerged by 2018 and became an influential codebase in the commodity stealer ecosystem. It is primarily known for harvesting credentials and other sensitive data from infected hosts, especially browser-stored information. Public reporting and detection metadata consistently characterize Arkei as a stealer, and multiple later malware families, most notably Vidar, are widely described as forks, variants, or descendants built from Arkei source code. Arkei-derived malware has also been linked through code lineage to later stealer families such as Oski and Mars, underscoring its importance as a foundational family in the evolution of credential theft malware.
Arkei targets Windows systems and focuses on theft of browser and application data. Available technical references indicate functionality associated with extracting data from Chromium- and Mozilla-based browsers, including use of browser-related components and SQLite-backed storage access typical of credential theft operations. As with other stealers in its lineage, Arkei is associated with collection of passwords and related user data, and it has been observed as a payload delivered by other malware, including the Retadup worm. The family is best understood as a commodity infostealer whose significance lies both in its own credential-theft role and in its reuse as a source code base for subsequent malware families.
No high-confidence, broadly corroborated attribution to a specific threat actor is established here. Likewise, the available material does not support a precise, high-confidence statement about a single dominant delivery vector for Arkei itself, beyond observations that it has been distributed as a secondary payload by other malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
rule win_arkei_stealer_auto { ... description = "Detects win.arkei_stealer." ... malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer" ... } ... rule win_arkei_stealer_w0 { ... description = "Arkei Stealer" ... $s1 = "Arkei" ... $s2 = "/server/gate" ... $s3 = "/server/grubConfig" ... $s4 = "\\files\\" ... $s5 = "SQLite" ... }
11 distinct techniques documented for this family, organized by ATT&CK tactic.
These DLLs are commonly downloaded and loaded into memory by stealers as they provide functionality to decrypt sensitive data within Mozilla Firefox and Chromium-based web browsers.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer whose source code was reportedly leveraged in Vidar's early development; mentioned as background lineage only.
Older stealer malware whose source code was used to develop Vidar.
Credential-stealing malware framework referenced as the basis from which Vidar originally developed.
Arkei is referenced only as the credential-stealer base from which Vidar originally evolved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.