Arkei Stealer is a Windows information-stealing malware family active by 2018 and known for harvesting passwords and cryptocurrency wallet material from infected systems. It has been associated with theft of browser-stored credentials and wallet private keys, and it has been referenced as an early code-relative or predecessor in discussions of later stealers such as Vidar, although the exact lineage between those families is disputed.
Arkei has appeared both in criminal experimentation and in real-world supply-chain-style compromise. A notable case involved a trojanized Windows cryptocurrency client installer that delivered Arkei to end users, demonstrating its use against cryptocurrency holders and systems managing digital assets. Reporting also links Arkei to underground operators experimenting with multiple commodity malware families.
The malware is notable for anti-analysis behavior aimed at the Windows Defender emulator. Observed samples checked emulator-associated host artifacts such as characteristic computer-name and username values and altered behavior when those conditions were met. This places Arkei among the earlier stealers documented using simple anti-emulation checks to evade automated analysis.
Arkei is best classified as an infostealer. High-confidence reporting supports credential theft and cryptocurrency-related data theft on Windows systems, but broader delivery patterns and additional capabilities are not consistently established from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer mentioned as the likely predecessor from which Vidar evolved.
Information-stealing malware noted here for using early Windows Defender emulator artifact checks (HAL9TH/JohnDoe) as an anti-emulation technique.
Referenced as the malware family from which Vidar originated.
Mentioned as a code-similar stealer often confused with Vidar, but stated as not related by the developer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.