Statc

Aliases: Statc Stealer, Static Stealer

First seen
2023-02-15 00:00:00
Malware type
credential-stealer, trojan
Family
Malware family
Profile updated
2026-07-07 15:21:23

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

This malicious software gains access to a victim’s data by appearing like an authentic Google advertisement. Once the victim clicks on the advertisement, their operating system is infected with malicious code that steals sensitive data like credentials from web browsers, credit card information, and cryptocurrency wallet details. Unauthorized access to a victim’s computer system can have enormous personal and professional repercussions. Victims become easy targets for identity theft, cryptojacking, and other forms of malware attacks. At the enterprise level, a Statc Stealer breach can result in financial loss, reputational damage, legal liabilities, and regulatory penalties.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Win_Malware_Statc_Downloader (yara-rule)
  • MALPEDIA_Win_Statc_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Statc (report)
  • zscaler.com — Statc Stealer Decoding Elusive Malware Threat (report)

External references