Skip to content

StealC

StealC is a Windows information stealer sold through a malware-as-a-service model since 2023.

Profile source: Mallory opens in a new tab

StealC

Family profile

StealC is a Windows information stealer sold through a malware-as-a-service model since 2023. Implemented in C and operated with a self-hosted control panel, it is designed to harvest sensitive data from infected systems, with a strong emphasis on browser-stored information. Reported collection targets include saved credentials, active session cookies, autofill data, messaging application data, email client data, FTP client data, gaming platform information, and cryptocurrency wallet data. Later iterations added encrypted handling of stolen data, and the malware is frequently described as modular.

StealC is commonly delivered as a secondary payload by loaders and staged malware chains, including SmartLoader and other commodity delivery frameworks. Observed distribution vectors include trojanized cracked or pirated software, SEO-poisoned fake software sites, fake browser-update lures, phishing-driven delivery chains, and ClickFix-style social-engineering pages that trick users into executing malicious commands. It has also appeared in broader shared distribution ecosystems that host multiple infostealer families and loaders.

Operationally, StealC is associated with commodity cybercrime activity rather than a single exclusive intrusion set. Its infrastructure and distribution have been disrupted in law-enforcement actions including Operation Endgame, which targeted ecosystems linked to StealC alongside other malware families. StealC remains widely encountered in telemetry and is used both for direct theft of consumer and enterprise data and as an enabler for follow-on account compromise, cloud access abuse, and resale of stolen credentials and session material.

Capabilities

  • Credential Theft
  • Exfiltration
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
60 IP / 37 hostnames

Leading locations

  • DE20
  • US20
  • NL12
  • CN10
  • RU6
  • KR4
  • LU4
  • IE2
  • KZ2
  • PL2
  • BG1
  • BR1

Leading providers

  • Cloudflare, Inc.6
  • Omegatech LTD6
  • Ghosty Networks LLC5
  • Amazon.com, Inc.4
  • FEMO IT SOLUTIONS LIMITED4
  • DEDIK SERVICES LIMITED3

Infrastructure traits

  • Hosting 74
  • Anycast 6
  • Vpn 2

Samples

Recent associated samples

Reported operators

Threat actors

17 named in public reporting
ByteToBreach

Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)

Plymouth

Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023.

Dungeon

A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”

YouTubeTA

StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.

SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

Crazy Evil

Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

Scarlet Goldfinch

If allowed to continue running beyond this stage, researchers have reported additional payloads including StealC and ArechClient2.

ZPHP

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

HANEYMANEY

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

EncryptHub

EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.

TA547

...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).

YouTube Ghost Network

Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.

UNC4108

Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).

TA582

Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).

SmartLoader

Hackers used a fake Oura MCP server to trick users into downloading malware that installs the StealC info-stealer... The trojanized version of the Oura MCP server delivers the StealC infostealer, targeting developer credentials, browser passwords, and cryptocurrency wallets.

GrayCharlie

These infections often progress to the deployment of Stealc and SectopRAT.

Exploited software

Vulnerabilities linked to StealC

1 CVEs

MITRE ATT&CK

StealC in ATT&CK

102 distinct techniques

Techniques

102 techniques
T1113 Screen Capture T1082 System Information Discovery T1027 Obfuscated Files or Information T1059.001 PowerShell T1071 Application Layer Protocol T1005 Data from Local System T1539 Steal Web Session Cookie T1555 Credentials from Password Stores T1105 Ingress Tool Transfer T1562 Impair Defenses T1566 Phishing T1204 User Execution T1036 Masquerading T1555.003 Credentials from Web Browsers T1189 Drive-by Compromise T1567 Exfiltration Over Web Service T1056 Input Capture T1557 Adversary-in-the-Middle T1195 Supply Chain Compromise T1566.002 Spearphishing Link T1589.001 Credentials T1078 Valid Accounts T1071.001 Web Protocols T1649 Steal or Forge Authentication Certificates T1053.005 Scheduled Task T1055 Process Injection T1204.002 Malicious File T1041 Exfiltration Over C2 Channel T1012 Query Registry T1497.003 Time Based Checks T1132 Data Encoding T1083 File and Directory Discovery T1027.007 Dynamic API Resolution T1057 Process Discovery T1059.003 Windows Command Shell T1218 System Binary Proxy Execution T1059 Command and Scripting Interpreter T1559.001 Component Object Model T1497 Virtualization/Sandbox Evasion T1070.004 File Deletion T1560 Archive Collected Data T1518 Software Discovery T1115 Clipboard Data T1497.001 System Checks T1614.001 System Language Discovery T1622 Debugger Evasion T1562.001 Disable or Modify Tools T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1574.001 DLL T1055.012 Process Hollowing T1003 OS Credential Dumping T1598 Phishing for Information T1587.001 Malware T1190 Exploit Public-Facing Application T1505.003 Web Shell T1068 Exploitation for Privilege Escalation T1528 Steal Application Access Token T1127 Trusted Developer Utilities Proxy Execution T1020 Automated Exfiltration T1033 System Owner/User Discovery T1608.001 Upload Malware T1119 Automated Collection T1584 Compromise Infrastructure T1059.006 Python T1552.001 Credentials In Files T1132.001 Standard Encoding T1573.001 Symmetric Cryptography T1480 Execution Guardrails T1486 Data Encrypted for Impact T1016 System Network Configuration Discovery T1055.004 Asynchronous Procedure Call T1027.013 Encrypted/Encoded File T1213 Data from Information Repositories T1219 Remote Access Tools T1199 Trusted Relationship T1218.005 Mshta T1059.007 JavaScript T1102 Web Service T1056.001 Keylogging T1586 Compromise Accounts T1583 Acquire Infrastructure T1566.003 Spearphishing via Service T1021.002 SMB/Windows Admin Shares T1566.001 Spearphishing Attachment T1583.008 Malvertising T1608.006 SEO Poisoning T1583.001 Domains T1588.001 Malware T1106 Native API T1583.004 Server T1573 Encrypted Channel T1036.005 Match Legitimate Resource Name or Location T1614 System Location Discovery T1070.006 Timestomp T1583.003 Virtual Private Server T1656 Impersonation T1129 Shared Modules T1070 Indicator Removal T1548.002 Bypass User Account Control T1204.001 Malicious Link T1027.002 Software Packing

Reporting

Research mentioning StealC

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

Aug 1
Hookphish

Ransomware Group qilin Hits: Schreiner Trockenbau GmbH

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.