Evrial is a Windows information-stealing Trojan sold on Russian-language criminal forums and observed in active distribution. It is designed to harvest browser cookies, stored credentials, desktop documents, screenshots, and cryptocurrency wallet data, then package and upload the collected material to attacker-controlled infrastructure through a web-based management panel. Reported credential theft targets include Chromium-based browsers and other common client applications, and the malware also steals Bitcoin wallet files when present on the victim system.
A defining feature of Evrial is clipboard hijacking for financial theft and account abuse. The malware monitors the Windows clipboard for cryptocurrency wallet strings and Steam trade URLs, uploads observed values to remote infrastructure, retrieves attacker-supplied replacements, and substitutes them into the clipboard so victims may unknowingly paste attacker-controlled destinations. This behavior supports theft involving multiple cryptocurrency ecosystems as well as Steam item trades.
Evrial has been marketed with a builder and administrative panel that allow operators to configure replacement strings and review clipboard activity, indicating a commodity crimeware model rather than a bespoke intrusion tool. It has also appeared in operations linked through shared actor identifiers and infrastructure to other commodity malware families including Vidar, Azorult, 1ms0rryStealer, Supreme miner, and DeathRansom. Reporting has associated some Evrial activity with the online personas scat01 and SoftEgorka, and more broadly with a Russian-speaking cybercriminal ecosystem.
High-confidence reporting supports Evrial as a credential- and data-theft malware family focused on Windows users, with particular emphasis on browser data theft, cryptocurrency theft, clipboard manipulation, screenshot capture, and exfiltration of stolen information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the individual claimed responsibility for creating several malware families, including Odysseus Project, Evrial, Ovidiy Stealer, and several others.
This sample is a non-obfuscated Evrial stealer. When we check its configuration, we see the following “Owner” field... “scat01”.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
By digging further among Super Info posts, we found an announcement about game accounts sales (Steam, WoT, Origin). Here we should note that stealers observed above are capable of stealing passwords from different games and game distribution platforms.
Evrial will also steal bitcoin wallets, stored passwords, documents from the victim's desktop, and a screenshot of the active windows.
In addition to monitoring and modifying the clipboard, Evrial will also steal bitcoin wallets, stored passwords, documents from the victim's desktop, and a screenshot of the active windows.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Non-obfuscated stealer whose configuration contains the owner field 'scat01'; also embedded inside Supreme miner samples distributed from gameshack[.]ru.
Named by the confessed author as one of several malware families he created and released.
Evrial is an information-stealing trojan that steals browser cookies, stored credentials, bitcoin wallets, desktop documents, and screenshots of active windows. It also monitors the Windows clipboard for cryptocurrency wallet addresses, WebMoney, Qiwi addresses, and Steam trade URLs, then replaces them with attacker-controlled values to hijack payments and trades.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.