Taurus is a Windows information-stealing malware family associated with the Predator the Thief cybercriminal group. It is designed to harvest credentials and other sensitive user data from a broad set of applications and services, including Chromium-based and Gecko-based browsers, cryptocurrency wallets, FTP clients, messaging applications, VPN software, email clients, and gaming-related platforms. Documented theft targets include passwords, cookies, autofill data, browsing history, session files, and host profiling data such as installed software and system configuration.
Observed Taurus campaigns used spam-delivered phishing documents that relied on malicious VBA macros to launch a multi-stage infection chain. After a victim enabled macros, the document executed PowerShell to retrieve additional components, used native Windows utilities to decode payloads, and leveraged AutoIt to decrypt and launch the stealer. Taurus has also been linked to related loader activity in broader crimeware distribution chains that use obfuscated AutoIt stages, persistence mechanisms, and in-memory execution before deploying credential-stealing payloads.
The malware incorporates multiple anti-analysis and defense-evasion measures. Reported techniques include timing-based sandbox detection using sleep-manipulation checks, host-based checks such as computer-name and file-based kill switches, internet-connectivity validation, and geographic exclusion logic intended to prevent execution in Commonwealth of Independent States countries. In observed execution chains, the final Taurus payload was injected into a legitimate Windows process to reduce visibility.
Once active, Taurus loads configuration data in memory, collects targeted data from supported applications, and packages stolen information into an in-memory ZIP archive for exfiltration. Its command-and-control endpoint can be constructed dynamically at runtime from obfuscated configuration data, complicating static analysis and detection. Taurus is best characterized as a commodity infostealer with mature evasion features and broad credential-access coverage, aimed at both individual users and organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the newest ones we observed, Taurus, includes techniques to evade sandbox detection. ... During our research, we observed that the "Predator the Thief" cybercriminal group is behind the development of this stealer, named Taurus.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The macro contains the URL of the payload as a combination of the following obfuscations: Base64 encoded and reversed string.
loads the deobfuscated shellcode for injecting the decoded payload into dllhost.exe.
PowerShell is using the Certutil.exe command to decode the payload and execute it on the victim's machine.
Stealing cookies, Auto-form details, browsing history, and credit card information from Chromium- and Gecko-based browsers.
This stealer also collects information, such as installed software and system configuration
we noticed that it has multiple anti-sandbox techniques. It checks for the Sleep patch in the sandbox using the GetTickCount function.
Threat hunters often focus on spotting command-and-control (C2) servers, open directories typically identified by the phrase “Index of” and phishing components.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware sold on dark forums that steals passwords, cookies, autofill data, browser history, credit card information, cryptocurrency wallet data, FTP and email client credentials, VPN credentials, chat/session data, and system information, then exfiltrates the stolen data to a C2 server in a ZIP archive. It uses malicious Office macros, PowerShell, AutoIt, shellcode injection into dllhost.exe, and anti-sandbox checks.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
Taurus is referenced only as a comparative stealer family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.