Eternity Stealer is a Windows information-stealing malware family sold under a malware-as-a-service model as part of the broader Eternity Project or EternityTeam criminal toolkit. Written in .NET, it has been marketed on underground forums and Telegram alongside related Eternity components such as a clipper, miner, worm, botnet or dropper, and ransomware. The operation appears financially motivated and organized around subscription-based access and builder-driven payload generation.
The malware is designed to harvest a wide range of sensitive data from infected systems. Documented collection targets include browser credentials, cookies, browsing history, bookmarks, autofill data, payment card data, cryptocurrency wallet data, browser-based wallet extensions, password managers, VPN clients, FTP clients, email clients, messaging applications, gaming-related credentials, and other locally stored secrets. Reported theft of session material such as browser cookies and Steam sessions indicates support for session hijacking in addition to credential theft. Stolen information is exfiltrated to attacker-controlled infrastructure and relayed to operators through Telegram bot workflows.
Eternity Stealer has been observed delivered through lure-based infection chains, including fake or themed software downloads aimed at gaming users and phishing campaigns targeting cryptocurrency and NFT communities. In observed campaigns, victims were directed to spoofed crypto-related sites that delivered malicious installers, after which staged downloaders retrieved and executed Eternity Stealer. Those delivery chains also showed defense-evasion behavior before payload deployment, including attempts to bypass User Account Control and weaken Microsoft Defender protections.
The malware primarily targets Windows hosts and has been associated with cybercrime activity focused on credential harvesting, account takeover, and theft of cryptocurrency-related assets. Its broad application coverage, Telegram-centric operator workflow, and MaaS commercialization make it notable within the commodity infostealer ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Eternity information stealer, advertised as the Eternity Stealer or Eternity Project, is the one that interests the most on forums... Eternity Stealer is a complete information stealer written in .NET and sold with the malware-as-a-service model for $99 per month.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware targets personal information from: several browsers (passwords, cookies, credit cards, autofill data, history, and bookmarks); browser cryptocurrency extensions; cryptocurrency wallets; numerous applications (password managers, messengers, VPN and FTP clients, and gaming software).
Browsers collection (Passwords, CreditCards, Cookies, AutoFill, Tokens, History, Bookmarks)
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET information stealer sold as malware-as-a-service that steals browser data, credentials, cookies, credit cards, autofill data, bookmarks, browser cryptocurrency extensions, cryptocurrency wallets, and data from password managers, messengers, VPN/FTP clients, gaming software, and Growtopia accounts. It exfiltrates stolen data via HTTPS POST to Eternity Team servers and forwards it through a Telegram bot.
Information stealer downloaded by the new NFT-001 staged downloader to exfiltrate browser credentials, cookies, VPN/FTP data, messaging app data, and password manager data.
An information stealer that exfiltrates browser data, email client data, messenger data, cryptocurrency wallets, password manager contents, VPN and FTP credentials, gaming sessions, and system credentials to a Telegram bot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.