Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2 / Distribution
- Host form
- 37 IP / 13 hostnames
SVCStealer is a Windows information-stealing malware family first observed in early 2025 and implemented in C++.
Profile source: Mallory opens in a new tabSVCStealer
SVCStealer is a Windows information-stealing malware family first observed in early 2025 and implemented in C++. It is primarily associated with spearphishing attachment delivery and has also been observed as a secondary payload in broader criminal malware distribution chains involving loaders and other stealers. The malware is designed to harvest a wide range of victim data, including system and software inventory, browser-stored information, user credentials, cryptocurrency wallet data, screenshots, messaging application data, VPN-related data, running process information, and selected user files. Reported browser targeting includes Chromium-based and other mainstream Windows browsers, and messaging-app targeting includes platforms such as Discord, Telegram, and Tox.
On infected hosts, SVCStealer gathers data into a local working directory, compresses the collected material into an archive, and exfiltrates it to attacker-controlled command-and-control infrastructure over HTTP POST traffic intended to blend with normal web activity. It generates a host-specific victim identifier derived from the system volume serial number and repeatedly beacons to its command infrastructure for registration and tasking. Beyond data theft, SVCStealer can receive instructions to download and execute additional payloads, making it useful both as an infostealer and as a follow-on malware delivery component.
The malware employs basic defense-evasion and anti-analysis measures. Reported behaviors include terminating common monitoring or process-inspection tools, enforcing single-instance execution, and deleting collected artifacts and archives after exfiltration to reduce forensic visibility. Operational reporting has linked SVCStealer to malware-as-a-service style ecosystems and to campaigns overlapping with other commodity crimeware families, including StealC and Diamotrix, indicating use within broader financially motivated intrusion chains rather than attribution to a single exclusive actor or cluster.
C2 tracking
Derp observations, rolling seven-day window
Samples
cd24f42e75ec240244754aba2b3c33c36622b2542ba69b5bcc0b26a40f205101 20b9236310a2ceaba13684b795dfe3db4281237f1681966422c98066f07c85bb 8c6ff2a22a3f412a6182bcdbed66daf753aca1f84b355ec7c747be3b7a9ea546 926c3d8e5e2dddd788189ece888d503e4d97c65f22b9c00fb4d5c68445aa08b9 9da4eb886a8667cf3277bcfb956f0a43e67fa6f432035069350a528ec05ff943 c9a14a9e0aff3962cb73e48a76d91a3743001e3da6d5376c75b56d8dd02b176f 084630e8d89789b946c5a8ecb6f5e91fee423b3b28df4c6cb2004c496b8ee72f 1378353e70a807b9d9c7d743ffec5fb4d34ff9497b0f41c80152c19556eeec6d 331ef7552e9e9aa60e4e3259e3d18b72da5b3b6afb8a2910f7641fd03a0efb00 654b3e412589ea4fc5e68d78823c0472852aa75824e8a243bdffe8a4ea2fd231 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.