DeerStealer Rootkit Stealer Campaign: Infrastructure and Defense
In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign.


In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign. This sophisticated form of malware leverages a variety of techniques to evade detection and steal sensitive information from targeted systems. As part of the infrastructure that supports this attack, cybercriminals rely on specific domains, IPs, and file hashes that can be tracked and blocked to help mitigate the attack’s effectiveness.
In this blog post, we’ll present an infrastructure map of the DeerStealer Rootkit Stealer Campaign, focusing on its various attack vectors, and provide a table of Indicators of Compromise (IOCs) that organizations can use to detect and block this threat in real time.
Understanding the DeerStealer Rootkit Stealer Campaign
The DeerStealer Rootkit Stealer is a sophisticated malware variant that utilizes multiple advanced techniques to infiltrate systems, hide its presence, and exfiltrate valuable information. Rootkits, in general, are malicious software components designed to provide persistent, stealthy access to an infected machine. What sets DeerStealer apart is its specific targeting of credential theft, its ability to hide under the radar, and its exploitation of both local and remote infrastructure.
Rootkit Characteristics and Capabilities
Persistence: Once installed, DeerStealer ensures its continued presence on the infected system by embedding itself deeply within the operating system, often using techniques such as kernel-mode rootkits. This makes it very difficult to detect using traditional security tools, which primarily focus on user-space processes.
Keylogger Functionality: DeerStealer is capable of monitoring user activity, capturing keystrokes, and stealing login credentials for various applications, especially browsers and email clients. These credentials are crucial for the attacker to access bank accounts, corporate networks, and other sensitive information.
C2 Communication: One of the hallmark features of DeerStealer is its reliance on Command and Control (C2) servers, which are used to manage infected machines, receive stolen data, and issue further commands to the compromised systems.
The campaign is organized into multiple stages:
Initial Access – The attacker typically gains access via phishing emails, exploiting vulnerabilities in software, or using social engineering tactics.
Payload Execution – Once access is gained, the malware installs itself and connects back to its C2 infrastructure.
Data Exfiltration – The stolen credentials and sensitive data are exfiltrated to remote locations, typically using encrypted or obfuscated communication methods.
Command and Control Communication – The malware regularly communicates with its C2 infrastructure, downloading additional payloads and ensuring persistence on the infected machine.
DeerStealer’s Infrastructure and Attack Vector

The DeerStealer Rootkit Stealer Campaign involves several layers of infrastructure, each designed to further the attacker’s ability to compromise, monitor, and control infected systems. These components include malicious domains, IP addresses, and file hashes, all of which are associated with the malware’s various stages of operation. Let’s take a deeper look at the technical aspects of this infrastructure:
Malicious Domains
The DeerStealer Rootkit Stealer relies heavily on custom malicious domains for various purposes, including:
C2 Server Communication: The malware uses these domains to establish an encrypted communication channel with the C2 server, allowing attackers to issue commands, receive stolen data, and deploy additional payloads.
Data Exfiltration: Sensitive information, including user credentials, is exfiltrated to these domains, where it is processed and then likely sold or used for other malicious purposes.
These domains are often chosen because they can be registered anonymously and can quickly be abandoned or moved, making them harder to track and block. Attackers frequently change domains, making it critical to stay updated with threat intelligence feeds to maintain detection capabilities.
Malicious IPs
The IP addresses associated with DeerStealer’s C2 servers are critical to understanding the infrastructure behind this malware. These IPs are often used for:
Command and Control Channels: These IPs allow the attacker to send commands to the infected machine, instructing it to download or upload data, further payloads, or maintain persistence on the system.
Exfiltration: Stolen credentials and sensitive data are often transmitted via these IPs to ensure the attacker maintains access and control over the compromised network.
By analyzing network traffic and correlating it with known malicious IPs, defenders can block these communication channels and sever the attack’s ability to operate.
Malicious File Hashes
One of the most critical aspects of defending against the DeerStealer Rootkit Stealer campaign is identifying and blocking malicious files using their file hashes. These hashes represent the unique identifiers for the files associated with the malware, ensuring that specific malicious binaries are detected and removed, even if the malware attempts to change its file name.
Malicious files often have embedded functionality such as:
Credential Stealing Mechanisms: These files contain the malicious code used to interact with browsers and steal stored credentials.
Persistence Mechanisms: These files ensure the malware remains undetected and active on the system even after reboots or system scans.
By monitoring file hashes and utilizing endpoint detection tools, organizations can ensure these files are quickly flagged and quarantined, reducing the risk of infection.
Indicators of Compromise (IOCs) for Blocking DeerStealer
To help organizations prevent and mitigate the impact of the DeerStealer Rootkit Stealer Campaign, it is essential to block the following Indicators of Compromise (IOCs). The table below lists the File Hashes, IP Addresses, and Domains associated with the malware:
| Type | Value | Date Added | Severity |
|---|---|---|---|
| File Hash (SHA-256) | 263484f65c76fd3be147ad124a1feaa5240a1d0ce1695855f08f6c6968d1a30d | Sep 20, 2025, 11:44:11 AM | High |
| File Hash (SHA-256) | 49ad6431fb67c29e1a2745092232898c491652ddf7115e0332382b42466d0734 | Sep 20, 2025, 11:44:11 AM | High |
| File Hash (SHA-256) | 5ec174af8a18a5516b8a6e11d8a27481d70df14d1edb67c48b5458ff44df9146 | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | 623ff1e6662986ab36336919fde5c48805b4a87b97af6f9abe09732e9ac45b8f | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | 6f1bfbb8ba6d4eb4e7ce3ff16f1b8e95d601a5eccdd0d743141ac7c3841b11f3 | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | a03cec07324b0c3227e4f060b0fefc24d35482dfe690bc86df1a53211629837e | Sep 20, 2025, 11:44:11 AM | High |
| File Hash (SHA-256) | b7ee370878fb4290097311e652222d8bab91c44a94063ea192100d4fd9dadb14 | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | ce62130f0392b40ab047392b47d523f66a55260c9fc2ec3d3727fab13fc87933 | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | d4b3a879fb6907c39a3b843ec5272a005e8fec25d8012c4a9fe9d0ada9f71d1f | Sep 20, 2025, 11:44:11 AM | Medium |
| File Hash (SHA-256) | e189e7fe9cd6d63ecece8b8e8fafb773003db6009fb0c45dc2b21e77167938ba | Sep 20, 2025, 11:44:11 AM | Medium |
| IP Address | 103.246.144.118 | Sep 20, 2025, 11:44:11 AM | High |
| Domain | loadinnnhr.today | Sep 20, 2025, 11:44:11 AM | High |
| Domain | nacreousoculus.pro | Sep 20, 2025, 11:44:11 AM | Medium |
| Domain | telluricaphelion.com | Sep 20, 2025, 11:44:11 AM | Medium |
How to Defend Against the DeerStealer Rootkit Stealer Campaign
Blocking the IOCs listed above is a crucial step in defending against the DeerStealer Rootkit Stealer campaign. However, there are additional best practices that organizations should implement to further protect their infrastructure:
Network Segmentation: Ensure that sensitive systems are isolated from general network traffic to prevent lateral movement of malware.
Endpoint Protection: Use advanced endpoint detection and response (EDR) tools to detect and respond to suspicious behavior.
Regular IOC Updates: Continuously monitor and update IOC lists to ensure that any new threats associated with DeerStealer are blocked.
Email and Web Filtering: Implement robust email and web filters to prevent phishing attacks and drive-by downloads from malicious websites.
User Awareness Training: Educate users on the dangers of clicking on unknown links and downloading attachments from suspicious sources.
Conclusion
The DeerStealer Rootkit Stealer campaign is an evolving and dangerous threat to organizations worldwide. By mapping the infrastructure behind these attacks, blocking key IOCs, and implementing strong defensive measures, companies can reduce the risk of falling victim to these sophisticated cybercriminal tactics.
Stay vigilant, regularly update your threat intelligence feeds, and ensure your security infrastructure is ready to detect and defend against this and other emerging threats.
Let us help you safeguard your environment. Contact us today for a comprehensive security review and a tailored defense strategy against advanced threats like DeerStealer.



