Security researchers identified a campaign distributing the DeerStealer infostealer through fake Google Authenticator websites and a GitHub-hosted lure posing as a legitimate authenticator application. Broadcom reported that the malware is written in Delphi and is designed to steal confidential data from compromised endpoints before sending it to attacker-controlled command-and-control infrastructure.
The stolen data is exfiltrated as PKZIP archives, underscoring DeerStealer’s role as a credential and information theft threat rather than a disruptive payload. Separate tracking from MalwareBazaar shows the malware family has been observed in the wild across at least 83 samples, with sightings in its database spanning from 2025-04-18 11:46:54 UTC to 2026-06-15 16:47:37 UTC, indicating continued circulation after the campaign was first documented.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
MalwareBazaar recorded its first-seen alert for the DeerStealer malware family, marking the earliest sample in its database for this signature. The database entry later indicated 83 samples had been identified as DeerStealer.
MalwareBazaar recorded the last-seen timestamp for DeerStealer in the referenced dataset. This marked the most recent observed sample among the 83 DeerStealer samples listed in the database entry.
Broadcom reported a malicious campaign distributing the DeerStealer infostealer as a fake Google Authenticator application hosted in a GitHub repository. The malware was described as Delphi-based and capable of stealing confidential data and exfiltrating it to attacker-controlled servers as PKZIP archives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.