Proofpoint reported that Ovidiy Stealer, a previously undocumented credential-theft malware family, was being actively sold and used in the wild, primarily in Russian-speaking cybercrime markets. The malware was advertised as a low-cost, modular tool and was observed in multiple rapidly updated versions, including 1.0.1 through 1.0.5, suggesting active development and broad accessibility for lower-skilled threat actors.
Ovidiy Stealer was distributed through malicious email attachments, direct executable downloads, and software-lure bundles such as fake installers. Once executed, it harvested credentials from web browsers and FileZilla and exfiltrated the data over SSL/TLS to the command-and-control domain ovidiystealer[.]ru. Proofpoint said the malware lacked persistence and stayed in its installation directory, appeared to reuse code from the open-source LiteHTTP Bot project, and was allegedly authored by an actor using the handle "TheBottle", with the same domain serving both as the malware sales portal and operational C2 infrastructure.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed original Ovidiy Stealer credential-stealing malware samples in the wild beginning in June 2017. The malware was previously undocumented and appeared to be marketed primarily in Russian-speaking regions.
By the time of its analysis, Proofpoint had seen Ovidiy Stealer versions 1.0.1 through 1.0.5 in circulation, indicating active development. The report also documented its distribution via malicious attachments, executable downloads, and software-lure bundles.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.