StealC is a cybercriminal malware-as-a-service infostealer that emerged in early 2023 and is advertised on Russian-speaking underground forums by the actor known as plymouth. It is operated as a self-service ecosystem in which customers generate builds and deploy their own administration panels and command-and-control infrastructure, producing a fragmented affiliate landscape rather than a single centrally managed operation. StealC is widely used as a replacement infostealer within the broader e-crime market and has been observed alongside other commodity malware delivery ecosystems. StealC is designed to steal credentials, browser cookies, cryptocurrency-wallet data, browser-extension data, autofill information, and selected files from infected systems. Reporting also links it to theft of session material and to downstream abuse such as credential stuffing and ransomware enablement. The malware has been distributed through multiple social-engineering and malware-delivery channels, including fake cracked-software lures on YouTube, malicious Blender files, malvertising chains, and techniques such as FileFix and fake CAPTCHA-style lures. The service has undergone active development, including a major V2 architectural update in 2025 and subsequent enhancements to its administration panel, notification features, payload delivery, and server-side log processing. Researchers have documented anti-analysis and defense-evasion features including runtime decryption and dynamic API resolution, as well as encrypted command-and-control communications. StealC operators and affiliates have also been affected by weaknesses in their own web panel security, including an exposed cross-site scripting flaw that enabled monitoring of operator sessions and theft of session cookies. StealC has been disrupted in coordinated operations targeting affiliate infrastructure, reflecting both its scale and its dependence on self-hosted criminal infrastructure. Available evidence supports classification of StealC as a financially motivated cybercrime operation centered on large-scale information theft and resale, with activity conducted by Russian-speaking operators and affiliates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An alternative infostealer/MaaS platform benefiting from customer migration away from Lumma Stealer.
Infostealer-as-a-service ecosystem whose affiliates self-host administration panels and infrastructure. It steals credentials, cookies, wallet data, browser extension data, and files matching operator-defined patterns; the report focuses on disruption of affiliate infrastructure and clustering of campaigns.
Operators/developers running a malware-as-a-service (MaaS) ecosystem for the StealC information stealer, including maintaining a web-based administration panel used by customers to manage infections, logs, and payload delivery.
Stealc is a MaaS infostealer targeting credentials, cookies, autofill data, and files from browsers, cryptocurrency wallets, and applications. It is actively developed, with regular updates and a robust admin panel, and is distributed via malvertising, malicious Blender files, and YouTube lures. Its logs are traded on underground markets and used for credential stuffing and as precursors to ransomware attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.