Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Malware Family

Mars Stealer

Also known as: Mars

Mars Stealer is an infostealer derived from the older Oski stealer that targets browser credentials, cookies, cryptocurrency wallets, and two-factor authentication browser extensions. It saw a surge in distribution through cracked-software and malvertising campaigns.

What is Mars Stealer?

Mars Stealer is an infostealer built on the lineage of the earlier Oski stealer. Sold on underground markets, it collects credentials, cookies, autofill, and cryptocurrency assets, and specifically targets browser extensions used for two-factor authentication and crypto wallets.

Distribution

Mars Stealer spread heavily through cracked software, key generators, and malvertising that placed malicious sites near the top of search results for popular applications. This made everyday users searching for free software a primary victim pool.

Why Mars matters

By targeting 2FA and wallet extensions directly, Mars Stealer increased the risk that a single infection would lead to account takeover and cryptocurrency theft, not just password exposure.

How VantaPrism Tracks Mars Stealer

VantaPrism ingests Mars Stealer logs and flags when stolen data includes session cookies or wallet artifacts, helping teams gauge whether an exposure could enable MFA bypass or financial theft.

Check Your Exposure arrow_forward

Frequently Asked Questions

What malware is Mars Stealer based on?

expand_more
Mars Stealer is derived from the older Oski stealer and shares much of its design.

Does Mars Stealer target cryptocurrency?

expand_more
Yes. Mars specifically targets cryptocurrency wallet files and browser extensions, as well as 2FA extensions.
← All Glossary Terms Last reviewed: June 2026