Skip to content

SVCStealer

SVCStealer is a Windows information-stealing malware family first observed in early 2025 and implemented in C++.

Profile source: Mallory opens in a new tab

SVCStealer

Family profile

SVCStealer is a Windows information-stealing malware family first observed in early 2025 and implemented in C++. It is primarily associated with spearphishing attachment delivery and has also been observed as a secondary payload in broader criminal malware distribution chains involving loaders and other stealers. The malware is designed to harvest a wide range of victim data, including system and software inventory, browser-stored information, user credentials, cryptocurrency wallet data, screenshots, messaging application data, VPN-related data, running process information, and selected user files. Reported browser targeting includes Chromium-based and other mainstream Windows browsers, and messaging-app targeting includes platforms such as Discord, Telegram, and Tox.

On infected hosts, SVCStealer gathers data into a local working directory, compresses the collected material into an archive, and exfiltrates it to attacker-controlled command-and-control infrastructure over HTTP POST traffic intended to blend with normal web activity. It generates a host-specific victim identifier derived from the system volume serial number and repeatedly beacons to its command infrastructure for registration and tasking. Beyond data theft, SVCStealer can receive instructions to download and execute additional payloads, making it useful both as an infostealer and as a follow-on malware delivery component.

The malware employs basic defense-evasion and anti-analysis measures. Reported behaviors include terminating common monitoring or process-inspection tools, enforcing single-instance execution, and deleting collected artifacts and archives after exfiltration to reduce forensic visibility. Operational reporting has linked SVCStealer to malware-as-a-service style ecosystems and to campaigns overlapping with other commodity crimeware families, including StealC and Diamotrix, indicating use within broader financially motivated intrusion chains rather than attribution to a single exclusive actor or cluster.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 14, 2026
Feed role
C2 / Distribution
Host form
37 IP / 13 hostnames

Leading locations

  • DE18
  • US9
  • CN3
  • KR3
  • NL3
  • FR2
  • IR2
  • RU2
  • GB1
  • HK1
  • IN1
  • TH1

Leading providers

  • FEMO IT SOLUTIONS LIMITED13
  • Omegatech LTD5
  • Farahoosh Dena PLC2
  • HostPapa2
  • ROUTE 95 LLC2
  • Shenzhen Tencent Computer Systems Company Limited2

Infrastructure traits

  • Hosting 40
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

SVCStealer in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.