Oski Stealer is a Windows information-stealing malware family first observed in late 2019 and derived from the Arkei lineage. It has been sold on Russian-language underground forums as a low-cost stealer and later served as the predecessor to Mars Stealer. The malware is written in C++ and uses string encryption, dynamic API resolution, and packed self-injection to hinder analysis. It also includes regional exclusion logic that avoids infecting systems configured for several CIS languages and anti-emulation checks associated with Windows Defender sandbox artifacts.
Oski Stealer is designed to harvest a broad range of victim data from browsers, email clients, and cryptocurrency wallet applications. Documented theft includes saved credentials, cookies, autofill data, payment card data, Outlook account information, cryptocurrency wallet files, system profiling data, screenshots, and attacker-selected user files. It supports theft from numerous browsers, including Chromium-based and Mozilla-based products, and implements logic to handle newer Chromium credential protection mechanisms. The malware also gathers host details such as operating system, hardware, language, user and computer identifiers, and related environment information.
Operationally, Oski Stealer creates a working directory under ProgramData, retrieves legitimate DLL dependencies from its command-and-control infrastructure, stores collected data in structured subdirectories, compresses the results into an archive, and exfiltrates the archive to its controller over HTTP POST. It also contains a configurable grabber component for recursive file collection and can act as a downloader by retrieving and executing additional payloads, making it useful as both a stealer and a follow-on malware delivery mechanism. Some samples remove their traces after execution through self-deletion routines.
Oski Stealer has been analyzed alongside Vidar and Mars Stealer because all three share Arkei-derived tradecraft, including retrieval of supporting DLLs and ZIP-based exfiltration workflows. Mars Stealer is widely assessed as Oski Stealer’s successor after Oski’s discontinuation in 2020.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Before diving into the stealer’s capabilities, it’s important to note that the malware uses two obfuscation techniques: Strings encryption Dynamic loading of DLLs and functions.
The second function Oski calls for after setting up all the strings in memory is procsSetup, which is responsible for loading different DLLs, resolving function addresses and saving the addresses within memory.
As soon as we opened the Oski stealer sample in IDA, we noticed that it was packed. In our case, the packer used a self-injection technique to pack Oski’s payload. It then unpacks the payload and writes it to a new memory region.
Self-Removal Oski removes its traces from the machine and deletes all the files, logs, DLLs, etc. from the disk.
it creates a new process of cmd.exe while the parameters for cmd.exe are /c /taskkill /pid <pid> & erase <path> & RD /S /Q <working_folder>\* & exit
The function decryptB64 gets the decryption key ... and the base64 string. decryptB64 decodes the base64 string and decrypts the decoded information by using RC4.
Oski steals login credentials, cookies, credit card and autofill information from 30+ different browsers using well-known and familiar stealing methods.
Oski updated its stealing technique regarding Chromium-based browsers and now supports the new method (v80+) by Chromium for encrypting credentials and cookies with a global AES key that is stored within %localappdata%\Google\Chrome\User Data\Local State and encrypted by using DPAPI.
Similar to other classic stealers, Oski gathers information about the system and takes a screenshot of the user’s desktop. It then writes the information to system.txt.
The second check is an anti-emulation check for Windows Defender Antivirus. The malware calls to GetComputerNameA and compares the computer name to HAL9TH. In addition, it checks if the username is JohnDoe.
Oski also has a recursive grabber that collects particular files from the victim’s computer... other attackers have intents to collect different files, like 2fa files, wallet files from different locations or even personal documents.
Oski creates a POST request to main.php in the C&C. In our case, the URL is http://sl9XA73g7u3EO07WT42n7f4vIn5fZH[.]biz/main.php.
During Vidar infections, the initial malware retrieves legitimate DLL files hosted on the same C2 server used for data exfiltration... Below are C2 domains used by the above samples... port 80... Vidar C2... Oski Stealer C2... Mars Stealer C2.
During Vidar infections, the initial malware retrieves legitimate DLL files hosted on the same C2 server used for data exfiltration... During Vidar infections, the initial malware binary requests each file from its C2 server... Like Vidar, Oski Stealer retrieves each of the legitimate DLL files separately... Current samples of Mars Stealer... retrieve legitimate DLL files as a single zip archive.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another malware family in passing; no substantive analysis provided in this content.
Credential and information stealer identified as the predecessor to Mars Stealer, sharing anti-emulation, self-removal, language checks, loader, and grabber capabilities.
An Arkei-based stealer variant that retrieves legitimate DLL files separately from its C2 server, using URLs that do not include the DLL filenames, and exfiltrates stolen host data as a zip archive.
An Arkei-based stealer variant that retrieves legitimate DLL files from its C2 server, using different URL patterns than Vidar, and exfiltrates stolen data from infected Windows hosts as ZIP archives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.