Skip to content

StealC

StealC is a Windows information-stealing malware family that emerged in 2023 and is commonly sold and operated as a malware-as-a-service offering in cybercrime ecosystems.

Profile source: Mallory opens in a new tab

StealC

Family profile

StealC is a Windows information-stealing malware family that emerged in 2023 and is commonly sold and operated as a malware-as-a-service offering in cybercrime ecosystems. It is written in C and is widely assessed as drawing on design elements from earlier stealers such as Arkei, while also incorporating concepts seen in other commodity infostealers. StealC is used to harvest sensitive data from web browsers, browser extensions, cryptocurrency wallets, email clients, and other applications, then exfiltrate the collected information to attacker-controlled infrastructure over HTTP, typically using POST requests. Reported theft targets include credentials, cookies, browser-stored data, wallet material, and related host information, and some campaigns have also involved screenshot capture and keylogging-related behavior tags.

StealC is frequently delivered through multi-stage intrusion chains rather than as a standalone first-stage payload. Observed delivery methods include malvertising, fake software-update lures, ClickFix-style social engineering, spam and spearphishing workflows, cracked-software lures, malicious GitHub repositories, and downloader or loader ecosystems involving malware such as Amadey, HijackLoader, MintsLoader, PrivateLoader, SmokeLoader, and RustyPita. Campaigns have used deceptive themes such as software activation tutorials, fake CAPTCHA or human-verification prompts, fake productivity-software downloads, and trojanized public code repositories. In several cases, users were tricked into manually executing PowerShell commands or launching staged installers that ultimately deployed StealC.

The malware commonly employs defense-evasion and anti-analysis measures. Reported samples have used XOR- or RC4-obfuscated strings, packing, staged dependency retrieval, and environment checks that terminate execution in likely sandbox or analyst environments. Documented checks have included username, language, CPU, memory, and display characteristics. Some delivery chains associated with StealC have also added security-product exclusions, used process injection, or relied on DLL sideloading and loader frameworks to reduce detection.

StealC has become a prominent commodity infostealer in the broader cybercrime market and has repeatedly appeared as an alternative chosen by operators migrating away from disrupted or unstable services such as Lumma Stealer. It has been observed in campaigns affecting a wide range of sectors and geographies, including enterprise users, telecom personnel, and organizations targeted through identity-centric intrusion activity. Law-enforcement and industry disruption efforts have targeted infrastructure associated with StealC alongside related malware ecosystems such as Amadey, underscoring its operational significance in contemporary credential-theft and data-exfiltration campaigns.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
147 IP / 126 hostnames

Leading locations

  • US88
  • DE37
  • CN22
  • NL22
  • RU13
  • HK12
  • IE9
  • KR8
  • PL8
  • LU6
  • FR4
  • SG4

Leading providers

  • Amazon.com, Inc.23
  • Cloudflare, Inc.16
  • Amazon.com, Inc.14
  • Omegatech LTD14
  • FEMO IT SOLUTIONS LIMITED13
  • Microsoft Corporation13

Infrastructure traits

  • Hosting 226
  • Anycast 17
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

18 named in public reporting
Plymouth

Stealc is an information stealer advertised on the underground forums XSS, Exploit and BHF by the Plymouth threat actor.

Marko Polo

Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic

ByteToBreach

Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)

Dungeon

A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”

YouTubeTA

StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.

SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

Crazy Evil

Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

Scarlet Goldfinch

If allowed to continue running beyond this stage, researchers have reported additional payloads including StealC and ArechClient2.

ZPHP

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

HANEYMANEY

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

EncryptHub

EncryptHub lured targets into installing AnyDesk, TeamViewer, and other remote monitoring and management software for lateral movement before utilizing PowerShell scripts that deliver the Rhadamanthys, Stealc, and Fickle Stealer infomation-stealing payloads.

TA547

...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).

YouTube Ghost Network

Others include StealC, RedLine, Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.

UNC4108

Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).

TA582

Confirmed TA582 payloads sharing this infrastructure: GhostWeaver/Pantera, MintsLoader, trojanized BOINC, CleanUpLoader, and StealC (per Recorded Future).

SmartLoader

Hackers used a fake Oura MCP server to trick users into downloading malware that installs the StealC info-stealer... The trojanized version of the Oura MCP server delivers the StealC infostealer, targeting developer credentials, browser passwords, and cryptocurrency wallets.

GrayCharlie

These infections often progress to the deployment of Stealc and SectopRAT.

Exploited software

Vulnerabilities linked to StealC

1 CVEs

MITRE ATT&CK

StealC in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1204.002 Malicious File T1555 Credentials from Password Stores T1555.003 Credentials from Web Browsers T1566 Phishing T1562 Impair Defenses T1564.001 Hidden Files and Directories T1059.001 PowerShell T1204 User Execution T1547.001 Registry Run Keys / Startup Folder T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1204.003 Malicious Image T1539 Steal Web Session Cookie T1078 Valid Accounts T1115 Clipboard Data T1059 Command and Scripting Interpreter T1041 Exfiltration Over C2 Channel T1027 Obfuscated Files or Information T1195 Supply Chain Compromise T1027.013 Encrypted/Encoded File T1055 Process Injection T1218 System Binary Proxy Execution T1112 Modify Registry T1518 Software Discovery T1071.001 Web Protocols T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1649 Steal or Forge Authentication Certificates T1036 Masquerading T1497.001 System Checks T1106 Native API T1176 Software Extensions T1547 Boot or Logon Autostart Execution T1059.007 JavaScript T1027.007 Dynamic API Resolution T1012 Query Registry T1053 Scheduled Task/Job T1070 Indicator Removal T1552 Unsecured Credentials T1083 File and Directory Discovery T1571 Non-Standard Port T1189 Drive-by Compromise T1566.002 Spearphishing Link T1113 Screen Capture T1140 Deobfuscate/Decode Files or Information T1129 Shared Modules T1059.003 Windows Command Shell T1620 Reflective Code Loading T1027.002 Software Packing T1005 Data from Local System T1001 Data Obfuscation T1057 Process Discovery T1070.004 File Deletion T1622 Debugger Evasion T1537 Transfer Data to Cloud Account T1056 Input Capture T1090 Proxy T1567 Exfiltration Over Web Service T1557 Adversary-in-the-Middle T1589.001 Credentials T1053.005 Scheduled Task T1497.003 Time Based Checks T1132 Data Encoding T1559.001 Component Object Model T1560 Archive Collected Data T1614.001 System Language Discovery T1562.001 Disable or Modify Tools T1574.001 DLL T1055.012 Process Hollowing T1003 OS Credential Dumping T1598 Phishing for Information T1587.001 Malware T1190 Exploit Public-Facing Application T1505.003 Web Shell T1068 Exploitation for Privilege Escalation T1528 Steal Application Access Token T1127 Trusted Developer Utilities Proxy Execution T1020 Automated Exfiltration T1033 System Owner/User Discovery T1608.001 Upload Malware T1119 Automated Collection T1584 Compromise Infrastructure T1059.006 Python T1552.001 Credentials In Files T1132.001 Standard Encoding T1573.001 Symmetric Cryptography T1480 Execution Guardrails T1486 Data Encrypted for Impact T1016 System Network Configuration Discovery T1055.004 Asynchronous Procedure Call T1213 Data from Information Repositories T1219 Remote Access Tools T1199 Trusted Relationship T1218.005 Mshta T1102 Web Service T1056.001 Keylogging T1586 Compromise Accounts T1583 Acquire Infrastructure T1566.003 Spearphishing via Service T1021.002 SMB/Windows Admin Shares

Reporting

Research mentioning StealC

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

Aug 1
Hookphish

Ransomware Group qilin Hits: Schreiner Trockenbau GmbH

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.