StealC is a Windows information-stealing malware family first publicly observed in 2023 and sold as a malware-as-a-service offering on Russian-speaking criminal forums. It is written in C and is widely used in both targeted intrusions and broad criminal distribution campaigns. StealC is commonly deployed as a final-stage payload by loaders and botnets including Amadey, HijackLoader, MintsLoader, PrivateLoader, and RustyPita, and it has also been distributed through malicious advertisements, fake software updates, phishing and ClickFix-style lures, cracked software, and trojanized GitHub repositories.
StealC focuses on theft of sensitive user data from browsers, browser extensions, cryptocurrency wallets, email clients, and other applications. Reported collection includes browser credentials, cookies, autofill data, wallet data, screenshots, and related host information. The malware exfiltrates stolen data to attacker-controlled infrastructure over HTTP, typically using POST requests. Multiple analyses also describe anti-analysis and anti-sandbox logic, including environment checks based on username, language, CPU count, memory, display characteristics, and virtualization artifacts. Some samples use obfuscated or encrypted strings, including RC4- or XOR-protected configuration data, and may retrieve additional runtime dependencies during execution.
Operationally, StealC is part of a broader cybercrime ecosystem and is frequently paired with commodity loaders, malvertising, social-engineering lures, and malware delivery services. It has appeared in campaigns themed around business services, fake CAPTCHA verification, software cracks, and cloned developer repositories. Infrastructure disruption efforts in 2026 targeted StealC alongside Amadey, reflecting its prominence in financially motivated intrusion activity. StealC is broadly associated with credential theft and follow-on criminal exploitation rather than destructive effects, and it remains a notable infostealer family in the Windows threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Developer tools: n8n workflows, CCNA labs, 7-Zip CVE-2025-0411 PoC, Cursor.so, Sora AI
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stealc is an information stealer advertised on the underground forums XSS, Exploit and BHF by the Plymouth threat actor.
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”
StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors are actively targeting public GitHub repositories that share tools such as game cheats, Claude code splitters, AI-powered security camera utilities, Amazon validators, coding extensions, and similar software. Attackers fork or clone legitimate repositories, then upload a malicious SmartLoader payload into them.
This blob contained a second PowerShell script, decoded and immediately invoked... The third and final script is responsible for downloading and executing the MSI installer.
The JavaScript code iterates through the array using the forEach method... If the user-agent contains “Chrome” or “Firefox”, the user will be served with a payload.
The Lua script is heavily obfuscated, and was obfuscated using the Prometheus Lua obfuscator.
In this campaign, the attacker-controlled GitHub repository hosts two XOR encoded distinct payloads
StealC was distributed via a malicious page serving a fake warning message prompting the user to download a security update to be able to use the store
The configuration retrieves the encrypted file from update-vinc.in[.]net, decrypts it, and injects it into the csc.exe process.
The Infostealer attempts to steal Browser Credential, browser cookies, Cryptocurrency Wallet and Email Client and Account Data.
Amadey is responsible for collecting information from infected machines, conducting C2 communications, and retrieving and executing additional payloads... As of 2026, the Amadey C2 communication that we have been able to confirm operates by encrypting binary data with an RC4 key, converting it into a hexadecimal string, and exchanging it in that form.
640 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware used to support ransomware intrusion chains by supplying stolen credentials and initial access.
An information-stealing malware deployed in a multi-stage infection chain involving a Rust-based loader, a fake GoogleTranslate Chrome extension, and an AutoIt script. It is used to steal browser-resident data such as cookies and stored credentials, supporting account hijacking and session theft.
An information stealer used to harvest browser credentials, cryptocurrency wallet data, and session tokens from infected systems.
An information-stealing malware family used to provide stolen credentials and access to ransomware operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.