SVCStealer is a Windows information-stealing malware family first observed in early 2025 and implemented in C++. It is primarily associated with spearphishing attachment delivery and has also been observed as a secondary payload in broader criminal malware distribution chains involving loaders and other stealers. The malware is designed to harvest a wide range of victim data, including system and software inventory, browser-stored information, user credentials, cryptocurrency wallet data, screenshots, messaging application data, VPN-related data, running process information, and selected user files. Reported browser targeting includes Chromium-based and other mainstream Windows browsers, and messaging-app targeting includes platforms such as Discord, Telegram, and Tox.
On infected hosts, SVCStealer gathers data into a local working directory, compresses the collected material into an archive, and exfiltrates it to attacker-controlled command-and-control infrastructure over HTTP POST traffic intended to blend with normal web activity. It generates a host-specific victim identifier derived from the system volume serial number and repeatedly beacons to its command infrastructure for registration and tasking. Beyond data theft, SVCStealer can receive instructions to download and execute additional payloads, making it useful both as an infostealer and as a follow-on malware delivery component.
The malware employs basic defense-evasion and anti-analysis measures. Reported behaviors include terminating common monitoring or process-inspection tools, enforcing single-instance execution, and deleting collected artifacts and archives after exfiltration to reduce forensic visibility. Operational reporting has linked SVCStealer to malware-as-a-service style ecosystems and to campaigns overlapping with other commodity crimeware families, including StealC and Diamotrix, indicating use within broader financially motivated intrusion chains rather than attribution to a single exclusive actor or cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Through an email, a YouTube video, a link, or a file masquerading as something legitimate, victims can unknowingly receive an entire malware bundle.
also ... processes running on the victim’s host[Windows_Info.txt] along with PID
This malware author harvests sensitive data such as machine data, installed software... also system information[System_info.txt]
capturing screenshots [Screenshot.jpg] , targeted files [extension] in the victim host
The infostealer collects various sensitive information from the infected endpoints such as system information, credentials, cryptocurrency wallets, data stored in browsers, screenshots, data from messaging applications (Discord, Tox, Telegram) or VPN apps, and others.
MITRE ATTACK TTPs: ... Credential Access T1056.001: Input Capture:Keylogging
After that, it tries to establish a connection to C2 server at port number 80. Once the C2 server connection has been established, TA uploads the collected details in the Post request
[TA0011][T1071.001] Outbound HTTP from Explorer.exe ... Port 80 | 443
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer malware observed as a payload in StealC-related infection chains.
SVCStealer was observed as a payload in StealC-related operations.
Information-stealing malware active since late 2024 that collects browser data, cryptocurrency wallet data, screenshots, and system information, archives the stolen data, and exfiltrates it to attacker-controlled PHP endpoints, often sharing infrastructure with Diamotrix.
A named malware family tracked by MalwareBazaar as SVCStealer; the content identifies it as a malware signature/family and implies it is an information-stealing malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.