This malware targets 2FA and crypto extensions, but only in Chromium-based browsers (opera is an exception).
In addition, the malware can extract valuable information on the targeted wallet, including processor model, computer name, machine ID, GUID, installed software and associated versions, username and computer domain.
Mars Stealer is able to exploit the following: 2FA plugins: • Authenticator, Authy, EOS Authenticator, GAuth Authenticator, Trezor Password Manager.
Crypto wallets: • Bitcoin Core and all derivatives (Dogecoin, Zcash, DashCore, LiteCoin, etc), Ethereum, Electrum, Electrum LTC, Exodus, Electron Cash, MultiDoge, JAXX, Atomic, Binance, Coinomi