StealC is a modular malware-as-a-service information stealer written in C and sold through a self-hosted control panel since early 2023. It is designed to harvest sensitive data from compromised Windows systems, with collection focused on browser-stored credentials, active session cookies, autofill data, messenger data, FTP client data, email client data, gaming-platform information, and cryptocurrency wallet data. Reporting also indicates theft of tokens and other session material that can enable account takeover without reauthentication.
StealC is commonly used as a follow-on payload in broader crimeware delivery chains rather than as a standalone initial vector. Observed campaigns have delivered it through trojanized cracked or pirated software, fake browser-update style lures, malicious GitHub repositories, and loader frameworks such as SmartLoader. In FakeGit and related AgentBaiting activity, victims were enticed to download ZIP-packaged fake developer tools, AI skills, or MCP server projects that executed a Lua-based loader chain, established persistence, retrieved additional encrypted stages, and ultimately launched or injected StealC. SmartLoader-linked activity has used scheduled tasks for persistence and blockchain-based configuration retrieval before deploying StealC.
StealC has also been observed injected into other processes as part of its execution chain, indicating process-injection-based evasion and execution support. Its role in commodity intrusion ecosystems is closely tied to credential theft and session hijacking, and stolen logs from families such as StealC are widely used by initial access brokers and downstream actors for cloud, SaaS, and enterprise account compromise.
The malware is part of the broader commodity infostealer landscape alongside families such as Lumma, RedLine, Vidar, Rhadamanthys, and Raccoon. It has appeared frequently in sandbox telemetry and has been linked to multiple distribution infrastructures later disrupted in law-enforcement operations, including Operation Endgame. StealC primarily targets Windows endpoints and is relevant across both consumer and enterprise environments because the data it steals can be reused for financial fraud, account takeover, follow-on phishing, and broader post-compromise access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Developer tools: n8n workflows, CCNA labs, 7-Zip CVE-2025-0411 PoC, Cursor.so, Sora AI
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023.
A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”
StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
Diversified Malware Toolkit: Crazy Evil uses advanced tools like Stealc and AMOS for Windows and macOS, ensuring widespread compromise.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
It spreads through phishing attachments, malvertising, drive-by downloads, and cracked software/keygen sites
There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware... Thousands of repositories are masquerading as AI skills or MCP servers... By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects.
Follow-on analysis of related FakeGit samples showed persistence through scheduled tasks under %LOCALAPPDATA%
Более 800 из них маскировались под навыки для ИИ-агентов и MCP-серверы... использовали имена настоящих разработчиков, накручивали звезды и форки, создавали правдоподобные README-файлы и копировали описания популярных инструментов.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
Техники Credentials from Web Browsers (T1555.003) и Steal Web Session Cookie (T1539) по MITRE ATT&CK описывают этот вектор... украденный cookie сессии позволяет войти в аккаунт в обход двухфакторной аутентификации.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
Техники Credentials from Web Browsers (T1555.003) и Steal Web Session Cookie (T1539) по MITRE ATT&CK описывают этот вектор. Инфостилеры - Lumma (LummaC2), StealC, Vidar, Rhadamanthys и другие ... вытаскивают из браузера сохранённые пароли...
SmartLoader establishes persistence on the compromised system and launches StealC, a malicious program capable of harvesting sensitive data from infected devices once it has been activated.
509 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular MaaS infostealer targeting browsers, FTP clients, messaging apps, email clients, gaming platforms, and cryptocurrency wallets. Distributed via phishing, malvertising, drive-by downloads, and cracked software/keygen sites.
A malware-as-a-service infostealer believed linked to Vidar developers that harvests a broad credential set. The content notes it was actively disrupted by Microsoft DCU in June 2026.
Infostealer described as stealing browser-saved passwords, session cookies, and autofill data.
A stealer malware mentioned only as prior infrastructure context linked to one of the operator's historical domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.