SVCStealer
- Malware type
- credential-stealer, botnet, screen-capture, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:55:56
- Profile updated
- 2026-07-07 15:21:56
Context
According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system. It collects sensitive information from the infected device such as system information, credentials, cryptocurrency wallets, data stored in browsers, screenshots, data from messaging applications such as Telegram or VPN apps. The collected information is compressed into a .zip archive and extracted to botnet C2 servers.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Svcstealer (report)
- seqrite.com — Svc New Stealer On The Horizon (report)
- rewterz.com — Svcstealer Malware Targeting Users To Extract Sensitive Data From Browsers And Applications Active Iocs (report)
- bazaar.abuse.ch — Svcstealer (report)
- Broadcom/Symantec — Svcstealer Malware (report)