Alpha Cyber

DeerStealer Rootkit Stealer Campaign: Infrastructure and Defense

In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign.

Alpha Cyber Research6 min readupdated 1 Apr 2026
Deer Stealer

DeerStealer Rootkit Stealer Campaign

In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign. This sophisticated form of malware leverages a variety of techniques to evade detection and steal sensitive information from targeted systems. As part of the infrastructure that supports this attack, cybercriminals rely on specific domains, IPs, and file hashes that can be tracked and blocked to help mitigate the attack’s effectiveness.

In this blog post, we’ll present an infrastructure map of the DeerStealer Rootkit Stealer Campaign, focusing on its various attack vectors, and provide a table of Indicators of Compromise (IOCs) that organizations can use to detect and block this threat in real time.

Understanding the DeerStealer Rootkit Stealer Campaign

The DeerStealer Rootkit Stealer is a sophisticated malware variant that utilizes multiple advanced techniques to infiltrate systems, hide its presence, and exfiltrate valuable information. Rootkits, in general, are malicious software components designed to provide persistent, stealthy access to an infected machine. What sets DeerStealer apart is its specific targeting of credential theft, its ability to hide under the radar, and its exploitation of both local and remote infrastructure.

Rootkit Characteristics and Capabilities

Persistence: Once installed, DeerStealer ensures its continued presence on the infected system by embedding itself deeply within the operating system, often using techniques such as kernel-mode rootkits. This makes it very difficult to detect using traditional security tools, which primarily focus on user-space processes.

Keylogger Functionality: DeerStealer is capable of monitoring user activity, capturing keystrokes, and stealing login credentials for various applications, especially browsers and email clients. These credentials are crucial for the attacker to access bank accounts, corporate networks, and other sensitive information.

C2 Communication: One of the hallmark features of DeerStealer is its reliance on Command and Control (C2) servers, which are used to manage infected machines, receive stolen data, and issue further commands to the compromised systems.

The campaign is organized into multiple stages:

Initial Access – The attacker typically gains access via phishing emails, exploiting vulnerabilities in software, or using social engineering tactics.

Payload Execution – Once access is gained, the malware installs itself and connects back to its C2 infrastructure.

Data Exfiltration – The stolen credentials and sensitive data are exfiltrated to remote locations, typically using encrypted or obfuscated communication methods.

Command and Control Communication – The malware regularly communicates with its C2 infrastructure, downloading additional payloads and ensuring persistence on the infected machine.

DeerStealer’s Infrastructure and Attack Vector

DeerStealer Rootkit Graph

The DeerStealer Rootkit Stealer Campaign involves several layers of infrastructure, each designed to further the attacker’s ability to compromise, monitor, and control infected systems. These components include malicious domains, IP addresses, and file hashes, all of which are associated with the malware’s various stages of operation. Let’s take a deeper look at the technical aspects of this infrastructure:

Malicious Domains

The DeerStealer Rootkit Stealer relies heavily on custom malicious domains for various purposes, including:

C2 Server Communication: The malware uses these domains to establish an encrypted communication channel with the C2 server, allowing attackers to issue commands, receive stolen data, and deploy additional payloads.

Data Exfiltration: Sensitive information, including user credentials, is exfiltrated to these domains, where it is processed and then likely sold or used for other malicious purposes.

These domains are often chosen because they can be registered anonymously and can quickly be abandoned or moved, making them harder to track and block. Attackers frequently change domains, making it critical to stay updated with threat intelligence feeds to maintain detection capabilities.

Malicious IPs

The IP addresses associated with DeerStealer’s C2 servers are critical to understanding the infrastructure behind this malware. These IPs are often used for:

Command and Control Channels: These IPs allow the attacker to send commands to the infected machine, instructing it to download or upload data, further payloads, or maintain persistence on the system.

Exfiltration: Stolen credentials and sensitive data are often transmitted via these IPs to ensure the attacker maintains access and control over the compromised network.

By analyzing network traffic and correlating it with known malicious IPs, defenders can block these communication channels and sever the attack’s ability to operate.

Malicious File Hashes

One of the most critical aspects of defending against the DeerStealer Rootkit Stealer campaign is identifying and blocking malicious files using their file hashes. These hashes represent the unique identifiers for the files associated with the malware, ensuring that specific malicious binaries are detected and removed, even if the malware attempts to change its file name.

Malicious files often have embedded functionality such as:

Credential Stealing Mechanisms: These files contain the malicious code used to interact with browsers and steal stored credentials.

Persistence Mechanisms: These files ensure the malware remains undetected and active on the system even after reboots or system scans.

By monitoring file hashes and utilizing endpoint detection tools, organizations can ensure these files are quickly flagged and quarantined, reducing the risk of infection.

Indicators of Compromise (IOCs) for Blocking DeerStealer

To help organizations prevent and mitigate the impact of the DeerStealer Rootkit Stealer Campaign, it is essential to block the following Indicators of Compromise (IOCs). The table below lists the File Hashes, IP Addresses, and Domains associated with the malware:

TypeValueDate AddedSeverity
File Hash (SHA-256)263484f65c76fd3be147ad124a1feaa5240a1d0ce1695855f08f6c6968d1a30dSep 20, 2025, 11:44:11 AMHigh
File Hash (SHA-256)49ad6431fb67c29e1a2745092232898c491652ddf7115e0332382b42466d0734Sep 20, 2025, 11:44:11 AMHigh
File Hash (SHA-256)5ec174af8a18a5516b8a6e11d8a27481d70df14d1edb67c48b5458ff44df9146Sep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)623ff1e6662986ab36336919fde5c48805b4a87b97af6f9abe09732e9ac45b8fSep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)6f1bfbb8ba6d4eb4e7ce3ff16f1b8e95d601a5eccdd0d743141ac7c3841b11f3Sep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)a03cec07324b0c3227e4f060b0fefc24d35482dfe690bc86df1a53211629837eSep 20, 2025, 11:44:11 AMHigh
File Hash (SHA-256)b7ee370878fb4290097311e652222d8bab91c44a94063ea192100d4fd9dadb14Sep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)ce62130f0392b40ab047392b47d523f66a55260c9fc2ec3d3727fab13fc87933Sep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)d4b3a879fb6907c39a3b843ec5272a005e8fec25d8012c4a9fe9d0ada9f71d1fSep 20, 2025, 11:44:11 AMMedium
File Hash (SHA-256)e189e7fe9cd6d63ecece8b8e8fafb773003db6009fb0c45dc2b21e77167938baSep 20, 2025, 11:44:11 AMMedium
IP Address103.246.144.118Sep 20, 2025, 11:44:11 AMHigh
Domainloadinnnhr.todaySep 20, 2025, 11:44:11 AMHigh
Domainnacreousoculus.proSep 20, 2025, 11:44:11 AMMedium
Domaintelluricaphelion.comSep 20, 2025, 11:44:11 AMMedium

How to Defend Against the DeerStealer Rootkit Stealer Campaign

Blocking the IOCs listed above is a crucial step in defending against the DeerStealer Rootkit Stealer campaign. However, there are additional best practices that organizations should implement to further protect their infrastructure:

Network Segmentation: Ensure that sensitive systems are isolated from general network traffic to prevent lateral movement of malware.

Endpoint Protection: Use advanced endpoint detection and response (EDR) tools to detect and respond to suspicious behavior.

Regular IOC Updates: Continuously monitor and update IOC lists to ensure that any new threats associated with DeerStealer are blocked.

Email and Web Filtering: Implement robust email and web filters to prevent phishing attacks and drive-by downloads from malicious websites.

User Awareness Training: Educate users on the dangers of clicking on unknown links and downloading attachments from suspicious sources.

Conclusion

The DeerStealer Rootkit Stealer campaign is an evolving and dangerous threat to organizations worldwide. By mapping the infrastructure behind these attacks, blocking key IOCs, and implementing strong defensive measures, companies can reduce the risk of falling victim to these sophisticated cybercriminal tactics.

Stay vigilant, regularly update your threat intelligence feeds, and ensure your security infrastructure is ready to detect and defend against this and other emerging threats.

Let us help you safeguard your environment. Contact us today for a comprehensive security review and a tailored defense strategy against advanced threats like DeerStealer.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]