SYMBOLCOMMON_NAMEaka. SYNONYMS
win.stealc (Back to overview)

Stealc

VTCollection    

Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.

Stealc is written in C and uses WinAPI functions. It mainly targets data from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.

References
2026-06-24BitSightBitsight TRACE
Amadey and StealC: Malware-as-a-Service Unavailable
Amadey Stealc
2026-06-24EuropolEuropol
Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks
FAKEUPDATES Amadey Stealc
2026-04-18Hexastrike CybersecurityMaurice Fielenbach
Cloned, Loaded, and Stolen: How 109 Fake GitHub Repositories Delivered SmartLoader and StealC
SmartLoader Stealc
2026-03-27Max's BlogMax Chertin
Analyzing StealC V2
Stealc
2026-02-12LevelBlueRodel Mendrez
How ClickFix Opens the Door to Stealthy StealC Information Stealer
IClickFix Stealc
2026-01-15CyberArkAri Novick
UNO reverse card: stealing cookies from cookie stealers
Stealc
2025-05-21TrendmicroJunestherry Dela Cruz
TikTok Videos Promise Pirated Apps, Deliver Vidar and StealC Infostealers Instead
Stealc Vidar
2025-05-11Avia Barazani
Breaking Down A Multi-Stage PowerShell Infection
Stealc
2025-05-01ZscalerThreatLabZ research team
I StealC You: Tracking the Rapid Changes To StealC
Stealc
2025-04-29Recorded FutureInsikt Group
Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting
FAKEUPDATES MintsLoader GhostWeaver Stealc TAG-124
2025-04-10Medium TRAC LabsTRAC Labs
Autopsy of a Failed Stealer: StealC v2
Stealc
2025-03-28Trend MicroAhmed Mohamed Ibrahim, Aliakbar Zahravi
A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
DarkWisp SilentPrism Kematian Stealer Rhadamanthys Stealc Water Gamayun
2025-03-04Hunt.ioHunt.io
Exposing Russian EFF Impersonators: The Inside Story on Stealc & Pyramid C2
Pyramid Stealc
2025-01-16eSentireeSentire Threat Response Unit (TRU)
MintsLoader: StealC and BOINC Delivery
MintsLoader Stealc
2025-01-10SpamhausSpamhaus Malware Labs
Spamhaus Botnet Threat Update July to December 2024
Coper FluBot Hook Mirai FAKEUPDATES AsyncRAT BianLian Brute Ratel C4 Cobalt Strike DanaBot DCRat Havoc Latrodectus NjRAT Quasar RAT RedLine Stealer Remcos Rhadamanthys Sliver Stealc
2024-10-17SekoiaQuentin Bourgue, Sekoia TDR
ClickFix tactic: The Phantom Meet
Rhadamanthys Stealc
2024-10-03LexfoLexfo
StealC Malware Analysis Part 3
Stealc
2024-10-03LexfoLexfo
StealC Malware Analysis Part 1
Stealc
2024-10-03LexfoLexfo
StealC Malware Analysis Part 2
Stealc
2024-08-15KasperskyAbdulRhman Alfaifi, Elsayed Elrefaei
Tusk campaign uses infostealers and clippers for financial gain
DanaBot HijackLoader Stealc
2024-06-17Recorded FutureInsikt Group
The Travels of “markopolo”: Self-Proclaimed Meeting Software Vortax Spreads Infostealers, Unveils Expansive Network of Malicious macOS Applications
AMOS Rhadamanthys Stealc Markopolo
2024-02-20YouTube (Embee Research)Embee_research
StealC Loader Analysis - Decoding Powershell Malware With CyberChef
Stealc
2024-01-30ANY.RUNLena (LambdaMamba)
CrackedCantil: A Malware Symphony Breakdown - PrivateLoader, Smoke, Lumma, RedLine, RisePro, Amadey, Stealc, Socks5Systemz, STOP
Amadey CrackedCantil Lumma Stealer PrivateLoader RedLine Stealer RisePro SmokeLoader Socks5Systemz Stealc STOP
2023-12-13cocomelonccocomelonc
Malware in the wild book
AsyncRAT Babuk BlackCat BlackLotus Carbanak HelloKitty Paradise Stealc WinDealer
2023-12-05Medium g0njxag0njxa
Approaching stealers devs : a brief interview with StealC
Stealc
2023-10-12SpamhausSpamhaus Malware Labs
Spamhaus Botnet Threat Update Q3 2023
FluBot AsyncRAT Ave Maria Cobalt Strike DCRat Havoc IcedID ISFB Nanocore RAT NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Stealc Tofsee Vidar
2023-10-03Glyc3rius
Stealc Malware Analysis
Stealc
2023-09-25EchoCTIBilal BAKARTEPE, bixploit
StealC Technical Analysis Report
Stealc
2023-08-24Github (muha2xmad)Muhammad Hasan Ali
StealC configuration extractor
Stealc
2023-08-15eSentireeSentire Threat Response Unit (TRU)
StealC Delivered via Deceptive Google Sheets
Stealc
2023-08-15Github (muha2xmad)Muhammad Hasan Ali
StealC string decryption
Stealc
2023-05-05VMRayVMRay Labs Team
Stealc: A new stealer emerges in 2023
Stealc
2023-02-27SekoiaQuentin Bourgue, Threat & Detection Research Team
Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity – Part 2
Stealc
2023-02-20SekoiaPierre Le Bourhis, Quentin Bourgue, Threat & Detection Research Team
Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity – Part 1
Stealc
2023-02-03CloudsekDeepanjli Paulraj, Pavan Karthick M
Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware
Alfonso Stealer Bandit Stealer Cameleon Fabookie Lumma Stealer Nanocore RAT Panda Stealer RecordBreaker RedLine Stealer Stealc STOP Vidar zgRAT
Yara Rules
[TLP:WHITE] win_stealc_auto (20260504 | Detects win.stealc.)
rule win_stealc_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-05-04"
        version = "1"
        description = "Detects win.stealc."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc"
        malpedia_rule_date = "20260422"
        malpedia_hash = "a182e35da64e6d71cb55f125c4d4225196523f14"
        malpedia_version = "20260504"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 83c460 e8???????? 83c40c }
            // n = 4, score = 600
            //   e8????????           |                     
            //   83c460               | add                 esp, 0x60
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc

        $sequence_1 = { 50 e8???????? e8???????? 81c484000000 }
            // n = 4, score = 600
            //   50                   | push                eax
            //   e8????????           |                     
            //   e8????????           |                     
            //   81c484000000         | add                 esp, 0x84

        $sequence_2 = { 68???????? e8???????? e8???????? 83c474 }
            // n = 4, score = 600
            //   68????????           |                     
            //   e8????????           |                     
            //   e8????????           |                     
            //   83c474               | add                 esp, 0x74

        $sequence_3 = { e8???????? e8???????? 83c418 6a3c }
            // n = 4, score = 600
            //   e8????????           |                     
            //   e8????????           |                     
            //   83c418               | add                 esp, 0x18
            //   6a3c                 | push                0x3c

        $sequence_4 = { e8???????? e8???????? 81c480000000 e9???????? }
            // n = 4, score = 600
            //   e8????????           |                     
            //   e8????????           |                     
            //   81c480000000         | add                 esp, 0x80
            //   e9????????           |                     

        $sequence_5 = { ff15???????? 85c0 7507 c685e0feffff43 }
            // n = 4, score = 600
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   7507                 | jne                 9
            //   c685e0feffff43       | mov                 byte ptr [ebp - 0x120], 0x43

        $sequence_6 = { 8d85dcf7ffff 50 8b450c 53 }
            // n = 4, score = 400
            //   8d85dcf7ffff         | lea                 eax, [ebp - 0x824]
            //   50                   | push                eax
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   53                   | push                ebx

        $sequence_7 = { 8d85dcf7ffff 50 ff15???????? 85c0 0f84a1000000 }
            // n = 5, score = 400
            //   8d85dcf7ffff         | lea                 eax, [ebp - 0x824]
            //   50                   | push                eax
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   0f84a1000000         | je                  0xa7

        $sequence_8 = { 0fb67588 440fb77586 440fb77d84 894c2470 498bcc 4489442468 }
            // n = 6, score = 300
            //   0fb67588             | movzx               eax, byte ptr [ebp - 0x72]
            //   440fb77586           | inc                 esp
            //   440fb77d84           | movzx               ecx, byte ptr [ebp - 0x73]
            //   894c2470             | mov                 edx, 0x69427551
            //   498bcc               | sub                 ecx, edx
            //   4489442468           | imul                eax, ecx, 0x14a30b

        $sequence_9 = { ba51754269 2bca 69c10ba31400 894d80 }
            // n = 4, score = 300
            //   ba51754269           | movzx               ecx, byte ptr [ebp - 0x71]
            //   2bca                 | dec                 esp
            //   69c10ba31400         | mov                 esp, eax
            //   894d80               | inc                 esp

        $sequence_10 = { e8???????? 0fb64d8f 4c8be0 440fb6458e 440fb64d8d 440fb6558c }
            // n = 6, score = 300
            //   e8????????           |                     
            //   0fb64d8f             | movzx               ecx, byte ptr [ebp - 0x71]
            //   4c8be0               | dec                 esp
            //   440fb6458e           | mov                 esp, eax
            //   440fb64d8d           | inc                 esp
            //   440fb6558c           | movzx               eax, byte ptr [ebp - 0x72]

        $sequence_11 = { ff15???????? 85c0 750a b043 }
            // n = 4, score = 300
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   750a                 | jne                 0xc
            //   b043                 | mov                 al, 0x43

        $sequence_12 = { e8???????? e8???????? 83c47c e9???????? }
            // n = 4, score = 300
            //   e8????????           |                     
            //   e8????????           |                     
            //   83c47c               | add                 esp, 0x7c
            //   e9????????           |                     

        $sequence_13 = { 894d80 2bc2 66894584 69c187fd701e b934eddb95 }
            // n = 5, score = 300
            //   894d80               | mov                 dword ptr [ebp - 0x80], ecx
            //   2bc2                 | sub                 eax, edx
            //   66894584             | mov                 word ptr [ebp - 0x7c], ax
            //   69c187fd701e         | imul                eax, ecx, 0x1e70fd87
            //   b934eddb95           | mov                 ecx, 0x95dbed34

        $sequence_14 = { 66894d86 69c90ba31400 2bca 884c0588 48ffc0 4883f808 7ceb }
            // n = 7, score = 300
            //   66894d86             | movzx               esi, word ptr [ebp - 0x7a]
            //   69c90ba31400         | inc                 esp
            //   2bca                 | movzx               edi, word ptr [ebp - 0x7c]
            //   884c0588             | mov                 dword ptr [esp + 0x70], ecx
            //   48ffc0               | mov                 word ptr [ebp - 0x7c], ax
            //   4883f808             | imul                eax, ecx, 0x1e70fd87
            //   7ceb                 | mov                 ecx, 0x95dbed34

        $sequence_15 = { 4533c0 4889442420 33c9 418d511c }
            // n = 4, score = 200
            //   4533c0               | mov                 dword ptr [ebp - 0x80], ecx
            //   4889442420           | sub                 eax, edx
            //   33c9                 | mov                 word ptr [ebp - 0x7c], ax
            //   418d511c             | imul                eax, ecx, 0x1e70fd87

        $sequence_16 = { 4883f808 7ceb 894d94 b925000000 e8???????? 0fb64d8f }
            // n = 6, score = 200
            //   4883f808             | movzx               edx, byte ptr [ebp - 0x74]
            //   7ceb                 | sub                 ecx, edx
            //   894d94               | imul                eax, ecx, 0x14a30b
            //   b925000000           | mov                 dword ptr [ebp - 0x80], ecx
            //   e8????????           |                     
            //   0fb64d8f             | sub                 eax, edx

        $sequence_17 = { 8b4580 0fb65d8a 0fb67d89 0fb67588 440fb77586 }
            // n = 5, score = 200
            //   8b4580               | movzx               esi, byte ptr [ebp - 0x78]
            //   0fb65d8a             | inc                 esp
            //   0fb67d89             | movzx               esi, word ptr [ebp - 0x7a]
            //   0fb67588             | inc                 esp
            //   440fb77586           | movzx               edi, word ptr [ebp - 0x7c]

        $sequence_18 = { 8bcc 8d959cfeffff 52 e8???????? e8???????? 83c40c 85c0 }
            // n = 7, score = 200
            //   8bcc                 | mov                 ecx, esp
            //   8d959cfeffff         | lea                 edx, [ebp - 0x164]
            //   52                   | push                edx
            //   e8????????           |                     
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   85c0                 | test                eax, eax

        $sequence_19 = { e9???????? 694d940ba31400 ba51754269 2bca }
            // n = 4, score = 200
            //   e9????????           |                     
            //   694d940ba31400       | movzx               esi, word ptr [ebp - 0x7a]
            //   ba51754269           | inc                 esp
            //   2bca                 | movzx               edi, word ptr [ebp - 0x7c]

    condition:
        7 of them and filesize < 4891648
}
[TLP:WHITE] win_stealc_w0   (20230221 | Find standalone Stealc sample based on decryption routine or characteristic strings)
rule win_stealc_w0 {
   meta:
       malware = "Stealc"
       description = "Find standalone Stealc sample based on decryption routine or characteristic strings"
       source = "SEKOIA.IO"
       reference = "https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/"
       classification = "TLP:CLEAR"
       hash = "77d6f1914af6caf909fa2a246fcec05f500f79dd56e5d0d466d55924695c702d"
       author = "crep1x"
       malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc"
       malpedia_version = "20230221"
       malpedia_license = "CC BY-NC-SA 4.0"
       malpedia_sharing = "TLP:WHITE"
       malpedia_rule_date = "20230221"
       malpedia_hash = ""
   strings:
       $dec = { 55 8b ec 8b 4d ?? 83 ec 0c 56 57 e8 ?? ?? ?? ?? 6a 03 33 d2 8b f8 59 f7 f1 8b c7 85 d2 74 04 } //deobfuscation function

       $str01 = "------" ascii
       $str02 = "Network Info:" ascii
       $str03 = "- IP: IP?" ascii
       $str04 = "- Country: ISO?" ascii
       $str05 = "- Display Resolution:" ascii
       $str06 = "User Agents:" ascii
       $str07 = "%s\\%s\\%s" ascii

   condition:
       uint16(0) == 0x5A4D and ($dec or 5 of ($str*))
}
Download all Yara Rules