FickerStealer, also known as Ficker, is a Windows information-stealing Trojan sold in Russian-speaking cybercrime forums and rented to other threat actors as a malware-as-a-service offering. It is designed to harvest sensitive data from infected systems, including saved credentials from web browsers, desktop messaging clients, and FTP software, as well as data from numerous cryptocurrency wallets. Reported collection behavior also includes theft of documents and capture of screenshots from active applications, after which the malware packages stolen data into an archive and exfiltrates it to the operator.
Observed distribution has included malicious advertising campaigns that impersonated legitimate software and services, including fake storefront and application download pages. In these campaigns, victims were redirected to deceptive landing pages that automatically delivered archive files containing the stealer disguised as legitimate software. Execution occurred when the victim extracted and launched the bundled executable.
FickerStealer is commonly discussed alongside other commodity infostealers such as RedLine, Vidar, and Raccoon due to its role in credential theft and broader data harvesting. Its primary operational purpose is theft of credentials and other monetizable victim data from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Referenced only as an example of a high-impact information stealer for comparison with BlackGuard.
Ficker is an information-stealing trojan marketed on Russian-speaking hacker forums and rented to other threat actors. It steals saved credentials from web browsers, desktop messaging clients, and FTP clients; can also steal cryptocurrency wallets and documents, take screenshots, package the stolen data into a ZIP archive, and exfiltrate it to the attacker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.