HomeSecurityMaranhão Stealer is distributed through pirated software

Maranhão Stealer is distributed through pirated software

Since May 2025, a new credential-stealing malware, known as Maranhão Stealer , has emerged as a significant threat to users of pirated software gaming . It is distributed via deceptive websites hosting cracked launchers and cheats, and leverages cloud hosting platforms to deliver innocent-looking trojanized installers

Maranhão Stealer

Upon execution, the installer unpacks a Node.js–compiled binary, embedded in an Inno Setup. It starts a discreet infection process that evades user detection while collecting sensitive data.

In its initial campaigns, malicious actors lured victims with attractive download links like DerelictSetup.zip, promising modified game content. In the background, however, the Inno Setup wrapper installs various components, including updater.exe, crypto.key, and infoprocess.exe, in a hidden “Microsoft Updater” directory under %localappdata%\Programs.

Cyble analysts noted that the malware establishes persistence  via Run registry keys and scheduled tasks, immediately after deployment.

See also: Phoenix RowHammer: Bypasses advanced DDR5 memory protections

The Maranhão Stealer's impact extends beyond simple credential theft. By injecting a reflective DLL into browser processes, the malware bypasses security measures such as AppBound encryption to extract saved passwords, cookies, and browsing history from Chrome, Edge, Brave, Opera, and other Chromium-based browsers.

Cyble researchers discovered that the malware also targets cryptocurrency wallets—Electrum, Exodus, Coinomi, and others—making it a dual threat to both traditional account credentials and digital asset wallets.

In addition to collecting credentials, Maranhão Stealer performs extensive system reconnaissance . It collects hardware and network information via WMI queries, profiles the operating system, CPU, disk space, and geographic location of the infected computer.

Screenshots captured via inline C# in PowerShell further enhance data theft capabilities, allowing malicious actors to monitor user activity in real time.

Maranhão Stealer is distributed through pirated software

Maranhão Stealer: The infection mechanism in more detail

A closer look at the infection mechanism reveals a multi-layered process designed for stealth and reliability. After executing the Inno Setup installer, the main payload (updater.exe) is launched in /VERYSILENT mode, suppressing any installation dialogs.

See also: Mustang Panda develops SnakeDisk USB Worm to distribute Yokai Backdoor

Persistence is immediately ensured with a registry modification. Once the Run key is in place, the malware marks its directory and files with hidden and system attributes via attrib +h +s (ensuring they remain hidden from casual inspection).

The next phase involves launching a helper process, infoprocess.exe, which injects a DLL payload directly into the current browser processes. Using low-level Windows APIs — NtAllocateVirtualMemory, NtWriteProcessMemory, and CreateThreadEx — the malicious module maps itself into the target's memory without touching the disk.

This reflective injection not only evades antivirus scans but also runs within legitimate browser executables, making detection even more difficult.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Combining social engineering, cloud distribution, and advanced injection tactics, Maranhão Stealer exemplifies the sophistication of modern credential stealing malware.

Maranhão Stealer is distributed through pirated software

Malware protection

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.

Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.

See also: BlackNevas Ransomware encrypts files and steals data

It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.

Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS