Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 147 IP / 126 hostnames
StealC is a Windows information-stealing malware family that emerged in 2023 and is commonly sold and operated as a malware-as-a-service offering in cybercrime ecosystems.
Profile source: Mallory opens in a new tabStealC
StealC is a Windows information-stealing malware family that emerged in 2023 and is commonly sold and operated as a malware-as-a-service offering in cybercrime ecosystems. It is written in C and is widely assessed as drawing on design elements from earlier stealers such as Arkei, while also incorporating concepts seen in other commodity infostealers. StealC is used to harvest sensitive data from web browsers, browser extensions, cryptocurrency wallets, email clients, and other applications, then exfiltrate the collected information to attacker-controlled infrastructure over HTTP, typically using POST requests. Reported theft targets include credentials, cookies, browser-stored data, wallet material, and related host information, and some campaigns have also involved screenshot capture and keylogging-related behavior tags.
StealC is frequently delivered through multi-stage intrusion chains rather than as a standalone first-stage payload. Observed delivery methods include malvertising, fake software-update lures, ClickFix-style social engineering, spam and spearphishing workflows, cracked-software lures, malicious GitHub repositories, and downloader or loader ecosystems involving malware such as Amadey, HijackLoader, MintsLoader, PrivateLoader, SmokeLoader, and RustyPita. Campaigns have used deceptive themes such as software activation tutorials, fake CAPTCHA or human-verification prompts, fake productivity-software downloads, and trojanized public code repositories. In several cases, users were tricked into manually executing PowerShell commands or launching staged installers that ultimately deployed StealC.
The malware commonly employs defense-evasion and anti-analysis measures. Reported samples have used XOR- or RC4-obfuscated strings, packing, staged dependency retrieval, and environment checks that terminate execution in likely sandbox or analyst environments. Documented checks have included username, language, CPU, memory, and display characteristics. Some delivery chains associated with StealC have also added security-product exclusions, used process injection, or relied on DLL sideloading and loader frameworks to reduce detection.
StealC has become a prominent commodity infostealer in the broader cybercrime market and has repeatedly appeared as an alternative chosen by operators migrating away from disrupted or unstable services such as Lumma Stealer. It has been observed in campaigns affecting a wide range of sectors and geographies, including enterprise users, telecom personnel, and organizations targeted through identity-centric intrusion activity. Law-enforcement and industry disruption efforts have targeted infrastructure associated with StealC alongside related malware ecosystems such as Amadey, underscoring its operational significance in contemporary credential-theft and data-exfiltration campaigns.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 329aa4b71b39b71b38c2b5140af2f7436242f1c1eddd80a419325e2bf7ee5665 3925905e8613a48f328a8f32854bc876498102690eff0d47cea9b50f97e43d2d 427727be19870488d1c57821e05448c09f72354cc271f4a91479301d7bfad865 8a7bf4eb7ab96502825949707b5dfcd761b4036e9539b655a5daeb6e24e61805 957158c4fb4ee442da50e7aa5899b6f663f85b793bdbd5fcfef5cedd079bfec1 Reported operators
Stealc is an information stealer advertised on the underground forums XSS, Exploit and BHF by the Plymouth threat actor.
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”
StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
If allowed to continue running beyond this stage, researchers have reported additional payloads including StealC and ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.
...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).
Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).
Hackers used a fake Oura MCP server to trick users into downloading malware that installs the StealC info-stealer... The trojanized version of the Oura MCP server delivers the StealC infostealer, targeting developer credentials, browser passwords, and cryptocurrency wallets.
These infections often progress to the deployment of Stealc and SectopRAT.
Exploited software
MITRE ATT&CK
Reporting
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.