Evil Stealer is a newly identified information-stealer malware-as-a-service (MaaS) operation reported by Breakglass Intelligence in March 2026. The operation was observed as a rapidly deployed cybercrime service associated with at least 310,194 processed credential logs, based on an exposed unauthenticated status API that returned a sequential last_log_id counter and the output directory name downloaded_logs. The malware ecosystem was assessed to include three monetization components: the Evil Stealer infostealer itself, a cryptocurrency wallet-draining capability embedded in the panel’s JavaScript, and a linked automated OnlyFans creator scraper branded OFM Hub Intel.
The known infrastructure centered on evilmirror[.]net, registered on March 4, 2026, resolving to 80.78.19[.]96 and hosted on Njalla infrastructure. The server exposed SSH on port 22, HTTP on port 80, HTTPS on port 443, a raw Next.js application on port 3000, and a Python BaseHTTP service on port 8888. The panel advertised version 0.6.6-rc and included the string "pragma evil >=0.6.6 <0.9.9;". The port 8888 service exposed a read-only unauthenticated /status endpoint that disclosed last_log_id 310194 and output_dir downloaded_logs. The actual malware payload, exfiltration channel, and infection or delivery vector were not identified in the reporting, and no Evil Stealer binary sample had been captured in public malware repositories or sandboxes as of publication.
The panel JavaScript contained the MetaMask API call eth_requestAccounts and a custom URI scheme evil_stealer://auth, leading investigators to assess that the web panel likely also functioned as a cryptocurrency wallet-draining trap for visitors. The panel referenced jabber.evilmirror[.]net for XMPP/OMEMO-style authentication, but the subdomain had no DNS record and relevant XMPP ports were closed, indicating that functionality was not operational at the time of analysis.
Breakglass Intelligence attributed the operation with high confidence to an operator using the Windows username "moros," based on unstripped XMP metadata embedded in the promotional video zloy_parya2.mp4 served by the panel. The metadata exposed the Adobe After Effects project path C:\Users\moros\Desktop\gfhz.aep, persistent XMP identifiers, and a creation timestamp of 2026-03-04T23:06:22+03:00. The filename and keyboard-layout analysis supported an assessment that the operator is likely Russian-speaking and working in UTC+3. The operation was also linked with high confidence to ofmhubintel[.]com at 80.78.19[.]92 through shared Namecheap registration, the same WHOIS privacy service, identical SSH HASSH fingerprint 41ff3ecd1458b0bf86e1b4891636213e, shared Njalla hosting, and matching Ubuntu 22.04/OpenSSH 8.9p1 deployment characteristics.
High-confidence indicators and artifacts directly mentioned in the reporting include evilmirror[.]net, 80.78.19[.]96, ofmhubintel[.]com, 80.78.19[.]92, jabber.evilmirror[.]net, the path /zloy_parya2.mp4, the custom URI scheme evil_stealer://auth, the MetaMask-related call eth_requestAccounts, the panel build identifier xeOeAnxdbPnm01dTsWk6f, the version string 0.6.6-rc, the semver string "pragma evil >=0.6.6 <0.9.9;", the XMP path C:\Users\moros\Desktop\gfhz.aep, and XMP identifiers xmp.iid:40395bd7-1b8b-bb49-aeb0-7bb8934ae858 and xmp.did:510e389b-1418-c04a-90bc-d51f2b53841b. The reporting noted that the 310,194 log counter appeared frozen, so some or all of the apparent credential volume may reflect migrated historical stolen-log data rather than current collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping Tactic Technique ID Application Credential Access Steal Application Access Token T1528 MetaMask wallet draining
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly observed stealer-as-a-service operation focused on credential theft. Its exposed backend status API indicated over 310,000 victim credential logs processed in about six days. The panel and infrastructure were rapidly deployed, but the actual payload sample, delivery mechanism, and victim-side behavior remain unknown.
An information stealer that harvests browser credentials, cookies, browser data, cryptocurrency wallet data, and other sensitive information from Windows victims. The associated panel also contains MetaMask wallet-draining functionality via eth_requestAccounts and a custom evil_stealer://auth URI scheme.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.