Doenerium is a Windows information stealer associated with commodity cybercrime distribution chains and observed as a payload in multiple malware delivery ecosystems. It has been used as an alternative final-stage payload in campaigns otherwise centered on other malware, including DUCKTAIL infection chains, and has also appeared in large-scale malvertising operations traced to illegal streaming and piracy-themed websites. In those campaigns, victims were redirected through multi-hop chains to GitHub-hosted payloads, and Doenerium was delivered alongside or in place of other stealers such as Lumma and Vidar. Doenerium has also been cited among Electron-based infostealers, indicating that at least some variants or related builds have used Electron for packaging or execution.
Operationally, Doenerium is best characterized as an infostealer focused on collecting sensitive data from compromised endpoints. High-confidence reporting links it to stealer activity rather than ransomware, destructive behavior, or worm-like propagation. It has been observed in campaigns targeting broad victim populations, including both consumer and enterprise devices, rather than a narrowly defined vertical. Its use in malvertising and lure-driven ecosystems suggests opportunistic targeting at scale, while its appearance in DUCKTAIL-related experimentation shows it can also be substituted into more tailored social-engineering chains.
Observed delivery mechanisms include malvertising and lure-based redirection from illegal streaming sites, as well as download chains involving public code-hosting and file-hosting services. In DUCKTAIL-related activity, Doenerium was deployed after archives and malicious shortcut-file execution chains that launched obfuscated PowerShell to retrieve later stages. Reporting also notes relationships between some GitHub-hosted payloads and the Doenerium malware family based on binary similarities and dropped components, with overlap in infrastructure historically associated with Lumma Stealer. Public attribution to a single threat actor is not established with high confidence, but the malware is clearly embedded in commodity cybercrime ecosystems and malware distribution operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft Threat Intelligence traced a December 2024 maladvertising campaign that reached nearly 1 million devices back to illegal streaming sites, where redirectors embedded in video frames funneled users through several hops to information stealers such as Lumma and Doenerium hosted on GitHub.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer delivered via redirect chains from illegal streaming sites in a maladvertising campaign affecting consumer and enterprise devices.
Referenced as an example of Electron-based infostealer malware seen in recent years.
Referenced as an example of Electron-based infostealer malware.
Information stealer distributed via fake video game download websites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.