StealC is a cybercriminal malware-as-a-service infostealer introduced in early 2023 and advertised on Russian-speaking underground forums by the actor using the moniker plymouth. It is operated as a fragmented affiliate ecosystem in which customers generate their own builds and run self-hosted administration panels and command-and-control infrastructure rather than relying on a single centrally managed backend. StealC has undergone active development, including a major V2 architectural update in 2025, and is widely used in commodity cybercrime operations. StealC is designed to steal browser credentials, cookies, autofill data, cryptocurrency-wallet data, browser-extension data, and selected files, and it has also been associated with theft of application data from common messaging and email clients. Reporting also links StealC activity to session theft and downstream account abuse, including credential-stuffing and account-takeover workflows. The malware uses encrypted command-and-control communications and incorporates anti-analysis and evasion features such as runtime decryption and dynamic API resolution. Researchers have also documented a web-based operator panel with role-based access and notification features. Observed delivery methods include fake software updates, cracked-software lures, YouTube-based social-engineering campaigns, malicious Blender files distributed through online marketplaces, malvertising chains, and delivery by third-party loaders. Campaigns have been observed globally. Public reporting has tied StealC infections to follow-on criminal activity and described it as a precursor or enabler for broader financially motivated intrusions, including ransomware-related operations. Known aliases and related references include StealC operators and the developer identity plymouth. StealC is best understood as a Russian-speaking cybercrime service ecosystem rather than a single tightly centralized intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer-as-a-service ecosystem whose affiliates self-host administration panels and infrastructure. It steals credentials, cookies, wallet data, browser extension data, and files matching operator-defined patterns; the report focuses on disruption of affiliate infrastructure and clustering of campaigns.
Operators/developers running a malware-as-a-service (MaaS) ecosystem for the StealC information stealer, including maintaining a web-based administration panel used by customers to manage infections, logs, and payload delivery.
Stealc is a MaaS infostealer targeting credentials, cookies, autofill data, and files from browsers, cryptocurrency wallets, and applications. It is actively developed, with regular updates and a robust admin panel, and is distributed via malvertising, malicious Blender files, and YouTube lures. Its logs are traded on underground markets and used for credential stuffing and as precursors to ransomware attacks.
StealC V2, linked to Russian threat actors, is used in campaigns targeting Blender users by distributing malicious .blend files to steal information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.