Collector Stealer is a Windows information-stealing malware family of suspected Russian origin that has been active since at least mid-2020. Written in C++, it is designed to harvest sensitive data from infected consumer systems and transmit the collected material to attacker-controlled command-and-control panels. Reported theft targets include stored browser passwords, cookies, autofill and other web data, screenshots, Telegram Desktop data, Steam-related information, and cryptocurrency wallet material. The malware has been observed targeting victims primarily in Europe, while also affecting users in other regions including the United States and Asia.
Collector Stealer is commonly distributed through social-engineering lures rather than exploit-driven intrusion. Observed delivery methods include phishing-style portals offering fake free games, counterfeit software downloads, and unauthorized activation or crack utilities. It has been bundled with riskware such as KMSAuto and disguised as game tools, miners, mod menus, and VPN-themed packages. In these campaigns, the visible lure application executes while a secondary process installs the stealer and begins communication with its control infrastructure.
On execution, Collector Stealer gathers host metadata such as computer name and time zone, uses obfuscated strings, and generates randomized filenames. It searches user directories for browser databases and application artifacts, including Telegram Desktop storage and Steam-related data. It can capture screenshots via keyboard-event simulation and clipboard access, and it scans desktop files for potentially valuable documents and connection files. To parse browser SQLite databases, it can retrieve a required SQLite library and then extract credentials, cookies, and related records in clear text. Stolen material is organized into directories and compressed into archives before exfiltration.
The malware performs an Internet-connectivity check before transmission and may delete itself along with staged stolen data if connectivity is unavailable, a behavior that reduces forensic residue and supports defense evasion. Exfiltration is performed over HTTP POST to attacker-operated panels. Collector Stealer has been marketed in Russian-language criminal ecosystems and has been associated with the Hack_Jopi group. Reporting has also noted code or lineage overlap with other stealers, including Panda Stealer, which has been described as a modified fork using more fileless delivery techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A modified fork of the malware Collector Stealer, Panda Stealer also utilizes a fileless approach in its distribution to evade detection.
Collector-stealer, a stealth stealer written in C++, infects the victim machine to steal valuable information such as stored passwords, cookies, web data and more, from the infected machine.
A modified fork of the malware Collector Stealer, Panda Stealer also utilizes a fileless approach in its distribution to evade detection.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The Collector-stealer author uses multiple methods to launch infections, which include coercing users to visit phishing portals hosting free game downloads, Windows activation/crack software packages, etc., to trigger drive-by download attacks that install the malware on the fly.
The Collector-stealer author uses multiple methods to launch infections, which include coercing users to visit phishing portals hosting free game downloads, Windows activation/crack software packages, etc., to trigger drive-by download attacks that install the malware on the fly.
Listing 1 highlights the pseudocode that Collector-stealer uses to deobfuscate the Windows public directory path address and other obfuscated strings using the key (string) ‘1A’.
The phishing web portal tricked users into believing that they had downloaded legitimate miner software, which was not the case.
Table 4 we correlate malware activity with MITRE ATT&CK TTP mapping... Query Registry Query HKCU for Steam entry
Collector-stealer creates a new command line sub-process to check Internet connectivity on infected machines by pinging Cloudflare DNS resolver IP address 1.1.1.1.
Collector-stealer also performs additional operations to extract the location ... along with the computer name by calling the GetComputerName method.
In Table 4 we correlate malware activity with MITRE ATT&CK TTP mapping... Data Staged: Local Data Staging Store collected data at //Public// directory.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russian-origin information stealer written in C++ that exfiltrates credentials, cookies, web data, Telegram and Steam session data, wallet files, desktop screenshots, and selected desktop documents. It is distributed via phishing portals, fake software/miner downloads, and bundled crack/riskware utilities, then archives stolen data and uploads it to attacker-controlled C2 panels over HTTP POST.
A stealer sold on underground forums and Telegram that exfiltrates cookies, login data, and web data from compromised systems, stores them in an SQLite3 database, and deletes stolen files and activity logs after execution. Panda Stealer is described as a variant/fork of it.
Credential and information stealing malware of Russian origin used to exfiltrate sensitive data from end-user systems to C&C panels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.