plymouth is the threat actor known for advertising and selling the StealC information stealer, a malware-as-a-service offering that emerged in 2023. StealC is a C++ infostealer that also functions as a secondary loader, enabling affiliates or customers to steal credentials, session cookies, autofill data, payment card data, browsing history, screenshots, extension data, application data, and selected files, and to download and execute additional payloads. The malware has been distributed through multiple initial access vectors, including other malware loaders such as Amadey and social-engineering lures such as ClickFix. StealC uses anti-analysis and defense-evasion measures including string obfuscation, dynamic API resolution, host-environment checks, and locale-based execution restrictions. It fingerprints infected systems extensively, communicates with command-and-control infrastructure over HTTP, retrieves tasking and configuration data, exfiltrates stolen information, downloads supporting components, and can deploy next-stage malware. Reported functionality includes theft from Chromium-based browsers and desktop applications such as messaging, email, file-transfer, and gaming clients, as well as file grabbing and optional execution of follow-on payloads. Operational reporting has linked the StealC ecosystem with shared infrastructure used alongside Amadey and placed it within the broader Russian-speaking cybercriminal malware market. StealC samples have been observed terminating on systems configured for Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan, consistent with CIS-region avoidance commonly seen in financially motivated cybercrime operations. Law-enforcement disruption activity in 2026 targeted infrastructure supporting the Amadey and StealC ecosystems, reflecting the scale of the operation and its role in credential theft and broader criminal intrusion chains. plymouth is best characterized as a financially motivated cybercriminal actor associated with the development, sale, or operation of the StealC malware service.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
137 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sells and maintains the StealC malware-as-a-service infostealer, which steals credentials, cookies, payment data, and other sensitive information and can also act as a secondary loader.
Advertises and is associated with the Stealc information stealer sold on underground forums; positioned within the Russian-speaking cybercriminal ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.