Oski is an information-stealing malware family used for credential theft. Reported capabilities include extracting browser credentials, cryptocurrency wallet addresses, and other sensitive information from infected systems. It has also been referenced in relation to Windows Defender emulator evasion research, where Oski was among stealer families observed using simple anti-emulation checks between 2018 and 2022. One cited technique involved checking emulator artifacts such as the computer name HAL9TH, username JohnDoe, or the file path C:\INTERNAL__empty.
Observed delivery included a campaign that abused compromised or exposed routers to redirect users attempting to visit legitimate domains to fake coronavirus-themed sites. Those sites redirected victims to Bitbucket pages hosting an Oski installer. In that activity, malicious DNS lookups were served from 109.234.35.230 and 94.103.82.249, and at least four Bitbucket accounts were used. Bitdefender observed the campaign beginning around March 18 and peaking on March 23, with Germany, France, and the United States among the most-targeted locations.
Oski is also referenced as a predecessor to Mars Stealer, with some claims suggesting Mars is a new version of Oski and later reporting describing Mars as an improved successor. Separately, leaked/cracked listings for OSKI Stealer appeared on the Russian-language cybercrime forum RAMP, indicating criminal-market availability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious-sites users land on claim to offer an app that provides “the latest information and instructions about coronavirus (COVID-19).” Users who click on the download button are ultimately redirected to one of several Bitbucket pages that offers a file that installs malware.
479 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer used for credential theft; a cracked version was offered on RAMP.
Stealer mentioned as using Windows Defender emulator artifact checks (HAL9TH/JohnDoe) for anti-emulation.
Referenced as the predecessor or possible earlier version related to Mars.
Information-stealing malware that extracts browser credentials, cryptocurrency wallet addresses, and possibly other sensitive information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.