Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Marco Stealer

Marco Stealer is a Windows-oriented information-stealing malware first observed in June 2025. It has been reported as being delivered via a downloader contained in a ZIP archive. The stealer is designed for financial theft and targets sensitive data from web browsers and cryptocurrency-related artifacts, including cryptocurrency wallet information from browser extensions. It also searches for and steals sensitive local files, including files in cloud-synced folders associated with popular cloud services such as Dropbox and Google Drive, which has been highlighted as a risk to corporate environments where sensitive documents may be synchronized.

Marco Stealer performs victim/system profiling by collecting details such as OS version, hardware ID, IP address, and geolocation, which is used to help operators prioritize higher-value victims. It includes anti-analysis features: it decrypts encrypted strings at runtime to hinder static analysis and scans for/attempts to terminate common analysis tools including Wireshark, x64dbg, and Process Hacker.

For data handling and exfiltration, Marco Stealer encrypts stolen data using AES-256 (reported as AES-256-CBC) with a key derived by hashing a hardcoded value, then exfiltrates via HTTP POST to a command-and-control server. Reported exfiltration includes an encrypted bundle containing a victim client ID, hardware ID, and stolen files.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence2

"distributed via a heavily obfuscated Inno Setup installer"; "Delivered via a downloader in a ZIP archive"; "illegally modified game installers distributed via piracy platforms"

T1497Virtualization/Sandbox EvasionEvidence2

"uses Windows APIs to detect anti-analysis tools like Wireshark, x64dbg, and Process Hacker"

Credential Access

2 techniques
T1555Credentials from Password StoresEvidence3

"LTX Stealer... conducts large-scale credential harvesting from Chromium-based browsers, targets cryptocurrency-related artifacts..."; "Marco Stealer... targets browser data, cryptocurrency wallet information..."

T1555.003Credentials from Web BrowsersEvidence1

“…designed to harvest sensitive data from browsers… It specifically targets browser data…”

Discovery

2 techniques
T1082System Information DiscoveryEvidence1

“Upon infection, the malware collects a wide range of system information, including the operating system version, hardware ID, IP address, and even the victim’s geographical location. This profiling allows attackers to sort their victims by value…”

T1497Virtualization/Sandbox EvasionEvidence2

"uses Windows APIs to detect anti-analysis tools like Wireshark, x64dbg, and Process Hacker"

Collection

2 techniques
T1005Data from Local SystemEvidence1

“It also hunts for ‘sensitive files (both locally and from cloud services)’…”

T1530Data from Cloud StorageEvidence1

“…specifically targeting files associated with Dropbox and Google Drive. This ability to reach into synced cloud folders…”

Command and Control

2 techniques
T1071.001Web ProtocolsEvidence1

"Stolen data is encrypted using AES-256 before being sent to C2 servers via HTTP POST requests"

T1573Encrypted ChannelEvidence1

“Marco Stealer uses ‘AES-256 CBC encryption to protect stolen data that is sent to its C2 server’… The malware generates a unique encryption key by hashing a hardcoded value…”

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence3

"Stolen data is encrypted using AES-256 before being sent to C2 servers via HTTP POST requests"

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

“Security Tool Termination: It actively scans for and attempts to kill analysis tools like Wireshark, x64dbg, and Process Hacker.”

ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.