plymouth is the moniker associated with the sale and operation of StealC, a commodity malware-as-a-service infostealer first observed in early 2023. StealC is a C++-based stealer that also functions as a secondary loader, enabling customers and affiliates to steal credentials, session cookies, autofill data, payment card information, browsing history, screenshots, selected files, and data from browser extensions and desktop applications. The malware can additionally download and execute follow-on payloads, making it useful both for standalone theft and as an access-and-delivery component in broader criminal intrusion chains. StealC has been distributed through multiple initial access vectors, including other malware loaders such as Amadey and social-engineering lures such as ClickFix. The operation has been linked to a broader commodity malware ecosystem used to support financial fraud, ransomware enablement, and attacks on critical infrastructure. Shared infrastructure between StealC and Amadey has been publicly reported, and both malware families have shown CIS-region avoidance behavior, including terminating or limiting activity on systems configured for certain locales. The actor behind StealC marketed the malware on a subscription basis, distinguishing it from some competing malware-as-a-service offerings by allowing ongoing build generation under that model. Public reporting has also documented security flaws in the StealC control panel that exposed operational details about the service and its customers, indicating an active affiliate or customer ecosystem around the malware. High-confidence reporting supports characterization of plymouth as a financially motivated cybercriminal operator tied to credential theft, session hijacking, data exfiltration, and malware delivery rather than as a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.