216.73.216.36

DeerStealer Malware Campaign: Stealth, Persistence, and Rootkit-Like Capabilities

· Published 20/09/2025 11:44 · Modified 22/09/2025 19:41

Export JSON

Essential information

Published
20/09/2025 11:44
Modified
22/09/2025 19:41
Tags
2025-09-20 data exfiltration deerstealer information-stealing multi-stage execution persistence rootkit stealth uac bypass xfiles spyware
Related entities
1 others

Description

is a sophisticated malware that targets a wide range of user and system data. It employs deception techniques, mechanisms, and -like capabilities to evade detection and maintain on compromised systems. The malware uses signed executables, legitimate DLLs, and to perform its malicious activities. It establishes through scheduled tasks and employs auto-elevated COM objects to bypass User Account Control. 's adaptive design allows it to switch C2 servers and use obfuscated files for effective . The malware is actively sold and supported through dark-web forums and Telegram channels, posing a significant threat to both individuals and organizations.

External references