Stealc

First seen
2023-01-09 00:00:00
Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 04:04:14
Profile updated
2026-07-07 13:13:52

Targeted industries: financial-services technology-and-telecommunications

Context

Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline. Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.

Detection coverage

  • 8 YARA rules

Detection rules

  • MALPEDIA_Win_Stealc_Auto (yara-rule)
  • RUSSIANPANDA_Win_Mal_Stealc_V2 (yara-rule)
  • EMBEERESEARCH_Win_Stealc_Bytecodes_Oct_2023 (yara-rule)
  • SEKOIA_Infostealer_Win_Stealc_Str_Oct24 (yara-rule)
  • CAPE_Stealcanti (yara-rule)
  • CAPE_Stealcstrings (yara-rule)
  • CAPE_Stealc (yara-rule)
  • CAPE_Stealcv2 (yara-rule)

Reports & references

  • recordedfuture.com — The Travels Of Markopolo Self Proclaimed Meeting Software Vortax Spreads Infostealers (report)
  • Trend Micro — Deep Dive Into Water Gamayun (report)
  • recordedfuture.com — Uncovering Mintsloader With Recorded Future Malware Intelligence Hunting (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • levelblue.com — How Clickfix Opens The Door To Stealthy Stealc Information Stealer (report)
  • esentire.com — Mintsloader Stealc And Boinc Delivery (report)
  • hunt.io — Russian Speaking Actors Impersonate Etf Distribute Stealc Pyramid C2 (report)
  • cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
  • any.run — Crackedcantil Breakdown (report)
  • cocomelonc.github.io — Malwild Book (report)
  • Kaspersky — 113367 (report)
  • blog.sekoia.io — Clickfix Tactic The Phantom Meet (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Stealc (report)
  • youtube.com — Watch (report)
  • blog.lexfo.fr — Stealc Malware Analysis Part1 (report)
  • blog.sekoia.io — Stealc A Copycat Of Vidar And Raccoon Infostealers Gaining In Popularity Part 1 (report)
  • zscaler.com — I Stealc You Tracking Rapid Changes Stealc (report)
  • blog.lexfo.fr — Stealc Malware Analysis Part2 (report)
  • glyc3rius.github.io — Stealc (report)
  • github.com — Stealc Technical Analysis Report (report)
  • aviab1.github.io — Powershell Infection 2025 (report)
  • cyberark.com — Uno Reverse Card Stealing Cookies From Cookie Stealers (report)
  • esentire.com — Stealc Delivered Via Deceptive Google Sheets (report)
  • g0njxa.medium.com — Approaching Stealers Devs A Brief Interview With Stealc Cbe5C94B84Af (report)

External references