SYMBOLCOMMON_NAMEaka. SYNONYMS
win.mystic_stealer (Back to overview)

Mystic Stealer

VTCollection    

According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants.
Mystic implements a custom binary protocol that is encrypted with RC4.

References
2023-06-15 ⋅ Zscaler ⋅ Brett Stone-Gross
Mystic Stealer: The New Kid on the Block
Mystic Stealer
Yara Rules
[TLP:WHITE] win_mystic_stealer_auto (20260917 | Detects win.mystic_stealer.)
rule win_mystic_stealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.mystic_stealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mystic_stealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 85f6 741a 8b4f6c 8b472c 2bce 2bc5 3bc8 }
            // n = 7, score = 300
            //   85f6                 | test                esi, esi
            //   741a                 | je                  0x1c
            //   8b4f6c               | mov                 ecx, dword ptr [edi + 0x6c]
            //   8b472c               | mov                 eax, dword ptr [edi + 0x2c]
            //   2bce                 | sub                 ecx, esi
            //   2bc5                 | sub                 eax, ebp
            //   3bc8                 | cmp                 ecx, eax

        $sequence_1 = { 83fd71 5d 5b 0f44c1 5e }
            // n = 5, score = 300
            //   83fd71               | cmp                 ebp, 0x71
            //   5d                   | pop                 ebp
            //   5b                   | pop                 ebx
            //   0f44c1               | cmove               eax, ecx
            //   5e                   | pop                 esi

        $sequence_2 = { 55 56 8b742414 57 8b460c 8b4e2c 83c0fb }
            // n = 7, score = 300
            //   55                   | push                ebp
            //   56                   | push                esi
            //   8b742414             | mov                 esi, dword ptr [esp + 0x14]
            //   57                   | push                edi
            //   8b460c               | mov                 eax, dword ptr [esi + 0xc]
            //   8b4e2c               | mov                 ecx, dword ptr [esi + 0x2c]
            //   83c0fb               | add                 eax, -5

        $sequence_3 = { 895614 8a4006 88040a 8b5614 }
            // n = 4, score = 300
            //   895614               | mov                 dword ptr [esi + 0x14], edx
            //   8a4006               | mov                 al, byte ptr [eax + 6]
            //   88040a               | mov                 byte ptr [edx + ecx], al
            //   8b5614               | mov                 edx, dword ptr [esi + 0x14]

        $sequence_4 = { 8b8f98160000 c6040100 8b8fa0160000 8b8798160000 41 }
            // n = 5, score = 300
            //   8b8f98160000         | mov                 ecx, dword ptr [edi + 0x1698]
            //   c6040100             | mov                 byte ptr [ecx + eax], 0
            //   8b8fa0160000         | mov                 ecx, dword ptr [edi + 0x16a0]
            //   8b8798160000         | mov                 eax, dword ptr [edi + 0x1698]
            //   41                   | inc                 ecx

        $sequence_5 = { ff7008 ff33 ff17 59 59 }
            // n = 5, score = 300
            //   ff7008               | push                dword ptr [eax + 8]
            //   ff33                 | push                dword ptr [ebx]
            //   ff17                 | call                dword ptr [edi]
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx

        $sequence_6 = { 8b4f48 8b4744 66892c48 45 8b8fb4160000 8b7774 }
            // n = 6, score = 300
            //   8b4f48               | mov                 ecx, dword ptr [edi + 0x48]
            //   8b4744               | mov                 eax, dword ptr [edi + 0x44]
            //   66892c48             | mov                 word ptr [eax + ecx*2], bp
            //   45                   | inc                 ebp
            //   8b8fb4160000         | mov                 ecx, dword ptr [edi + 0x16b4]
            //   8b7774               | mov                 esi, dword ptr [edi + 0x74]

        $sequence_7 = { 8d7ffe 33c9 0fb707 8bd0 2bc5 3bd6 }
            // n = 6, score = 300
            //   8d7ffe               | lea                 edi, [edi - 2]
            //   33c9                 | xor                 ecx, ecx
            //   0fb707               | movzx               eax, word ptr [edi]
            //   8bd0                 | mov                 edx, eax
            //   2bc5                 | sub                 eax, ebp
            //   3bd6                 | cmp                 edx, esi

        $sequence_8 = { 0f43c8 66890b 83ed01 75e4 }
            // n = 4, score = 300
            //   0f43c8               | cmovae              ecx, eax
            //   66890b               | mov                 word ptr [ebx], cx
            //   83ed01               | sub                 ebp, 1
            //   75e4                 | jne                 0xffffffe6

        $sequence_9 = { 2408 02c8 837d1000 0f94c0 fec8 2404 02c8 }
            // n = 7, score = 300
            //   2408                 | and                 al, 8
            //   02c8                 | add                 cl, al
            //   837d1000             | cmp                 dword ptr [ebp + 0x10], 0
            //   0f94c0               | sete                al
            //   fec8                 | dec                 al
            //   2404                 | and                 al, 4
            //   02c8                 | add                 cl, al

    condition:
        7 of them and filesize < 512000
}
Download all Yara Rules