Mars is an information-stealing malware family first observed in 2021 and advertised as a standalone stealer on cybercriminal forums, Telegram channels, and darknet sites. It primarily targets Windows victim credentials, cryptocurrency wallets, associated 2FA plugins, and essential system information. Reported capabilities also include downloading and executing additional files from a specified drop-zone, extending it beyond pure credential theft.
The available content describes Mars as gaining traction as a low-cost, beginner-friendly infostealer option, with some actors comparing it favorably to Raccoon Stealer and some claims portraying it as a new or improved version of Oski Stealer. It was promoted by operators branding themselves as “MarsTeam,” including via an official Telegram sales channel created on 2021-08-04. Mars was advertised across more than 47 underground forums, Telegram channels, and onion sites, and was offered as a lifetime subscription for $160 payable in cryptocurrency. A leaked Mars panel version was also available for free, though users had to manage their own infrastructure and anonymity without operator support.
Mars is also referenced as one of the stealers whose features or ideas reportedly influenced the development of Stealc. Separately, the content notes that Mars was among malware families observed using simple Windows Defender emulator artifact checks such as the computer name HAL9TH and username JohnDoe between 2018 and 2022. No additional high-confidence Mars-specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer mentioned as using Windows Defender emulator artifact checks (HAL9TH/JohnDoe) for anti-emulation.
Referenced as one of the prominent stealers Stealc's development relies on.
Mars is referenced as one of the infostealers Stealc's development relied on and as a comparable malware family that also downloads legitimate third-party DLLs.
Information stealer targeting Windows credentials, cryptocurrency wallets, 2FA plugins, and system information. It can also download and execute additional files from a drop-zone.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.