Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 60 IP / 37 hostnames
StealC is a Windows information stealer sold through a malware-as-a-service model since 2023.
Profile source: Mallory opens in a new tabStealC
StealC is a Windows information stealer sold through a malware-as-a-service model since 2023. Implemented in C and operated with a self-hosted control panel, it is designed to harvest sensitive data from infected systems, with a strong emphasis on browser-stored information. Reported collection targets include saved credentials, active session cookies, autofill data, messaging application data, email client data, FTP client data, gaming platform information, and cryptocurrency wallet data. Later iterations added encrypted handling of stolen data, and the malware is frequently described as modular.
StealC is commonly delivered as a secondary payload by loaders and staged malware chains, including SmartLoader and other commodity delivery frameworks. Observed distribution vectors include trojanized cracked or pirated software, SEO-poisoned fake software sites, fake browser-update lures, phishing-driven delivery chains, and ClickFix-style social-engineering pages that trick users into executing malicious commands. It has also appeared in broader shared distribution ecosystems that host multiple infostealer families and loaders.
Operationally, StealC is associated with commodity cybercrime activity rather than a single exclusive intrusion set. Its infrastructure and distribution have been disrupted in law-enforcement actions including Operation Endgame, which targeted ecosystems linked to StealC alongside other malware families. StealC remains widely encountered in telemetry and is used both for direct theft of consumer and enterprise data and as an enabler for follow-on account compromise, cloud access abuse, and resale of stolen credentials and session material.
C2 tracking
Derp observations, rolling seven-day window
Samples
c48383f092309dc531d84c5fb3493ef1b10cd31c80240890a292341fb3530469 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 6ff59d49647c897e8c134519f5eb73ff53bd55386a24c55058e7427598d5a754 8e2b78e7c586e36dc3b27c78466fad735f86cdd9b4e7ecbc4c650d934a9a176b 9ba1fdde2cc64be99ce8b98fa34cd602949d13c72a7b84fa5da6828cec12c5d9 Reported operators
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023.
A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”
StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
If allowed to continue running beyond this stage, researchers have reported additional payloads including StealC and ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.
...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).
Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).
Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).
Hackers used a fake Oura MCP server to trick users into downloading malware that installs the StealC info-stealer... The trojanized version of the Oura MCP server delivers the StealC infostealer, targeting developer credentials, browser passwords, and cryptocurrency wallets.
These infections often progress to the deployment of Stealc and SectopRAT.
Exploited software
MITRE ATT&CK
Reporting
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.