ColdStealer is a .NET-based information-stealing malware family distributed through fake software downloads themed as cracks and tools, typically via a dropper and downloader infection chain. It has also been observed as a payload delivered by NullMixer. The malware uses multiple packing and obfuscation layers, with reported variants employing .NET obfuscation and earlier samples using process hollowing and .NET loading techniques to hinder analysis and detection.
Its primary purpose is theft of user and system data from Windows hosts. ColdStealer targets browser-stored credentials, cookies, and other web data from Chromium-based browsers as well as Opera and Firefox. It also enumerates installed browser extensions and selectively steals data associated with cryptocurrency wallet and authentication-related extensions. Beyond browser theft, it harvests cryptocurrency wallet application data, FileZilla FTP credentials, selected user files, clipboard contents, and host profiling information such as Windows version, language, CPU type, and execution privilege level.
ColdStealer parses browser data internally and exfiltrates selected information rather than simply stealing entire browser databases. Collected data is compressed into an in-memory ZIP stream instead of being written to disk, reducing forensic artifacts. The malware then transmits the stolen information to command-and-control infrastructure over HTTP POST. It also records and exfiltrates runtime exceptions, indicating operator interest in telemetry and malware reliability. Reported behavior includes a Unicode-handling flaw that can trigger SQLite parsing errors on Korean-language Windows systems.
ColdStealer is best characterized as an infostealer focused on credentials, browser session material, cryptocurrency wallet data, FTP access, and other victim information useful for account compromise and financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Files in the desktop and subdirectories of the user account are targeted. The malware collects any files that have a “wallet” string or extensions .txt and .dat.
Collects various system information including Windows version, language, CPU type, clipboard data, execute permission, etc.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer targeting crypto wallets, FTP credentials, and browser credentials.
A .NET information-stealing malware delivered via a dropper/downloader chain disguised as cracked software or tools. It collects browser credentials, cookies and web data, cryptocurrency wallet data, files, FTP credentials, system information, and exception/error data, packages stolen data in an in-memory ZIP stream to reduce disk artifacts, and exfiltrates it to a hardcoded C2 over HTTP POST.
ColdStealer is a .NET-based infostealer distributed via dropper/downloader chains disguised as software cracks and tools. It steals browser credentials, cookies and web data, cryptocurrency wallet data, desktop files matching wallet/.txt/.dat patterns, FileZilla FTP credentials, and system information, then compresses stolen data in memory as ZIP streams and exfiltrates it to a hard-coded C2 over HTTP POST. It also records and sends execution errors/exceptions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.