StealC is a Windows information-stealing malware family used to collect browser-resident credentials, saved passwords, locally stored application credentials, and authenticated browser cookies. Theft of active session cookies enables session hijacking, allowing attackers to reuse authenticated sessions without completing a new password or multifactor-authentication flow. StealC has been identified in incidents involving theft and abuse of Claude account sessions and has been associated with compromised credentials subsequently used in espionage-oriented phishing activity. It is also used in social-engineering campaigns that pose as software-activation or premium-feature tutorials on social-media platforms and induce victims to execute PowerShell commands. Such campaigns have deployed StealC, added security-product exclusions, concealed execution, created startup persistence, and contacted attacker-controlled infrastructure after infection. StealC activity has also been observed in dedicated campaigns affecting enterprise environments. In June 2026, its infrastructure was targeted in a Microsoft-announced operation alongside Amadey infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Developer tools: n8n workflows, CCNA labs, 7-Zip CVE-2025-0411 PoC, Cursor.so, Sora AI
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stealc is an information stealer advertised on the underground forums XSS, Exploit and BHF by the Plymouth threat actor.
Recorded future unveiled in June 2024 that Atomic stealer is likely spread by the alias ‘markopolo’, an IAB spreading StealC, Rhadamanthys and Atomic
Deux bots infostealer originaires d’Algérie contenant ses identifiants (infectés par Raccoon en septembre 2022 et StealC en février 2024)
A user named @amdfx6300 on the Lolz Guru forum posted a thread titled “[LOGS] Dungeon Team Reborn · Stealc V2/Rhadamanthys · Fud Loader (0VT) / Fud Crypt | Seo Yt/Github.”
StealC, on the other hand, has leveraged various initial access vectors ranging from malware loaders (including Amadey) and ClickFix lures, and is equipped to extract sensitive information, such as screenshots, credentials, session cookies, autofill entries, credit card data, browsing history, and extension data. ... It also acts as a secondary loader, capable of downloading and executing EXE, MSI, or PowerShell payloads based on commands from an external server.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
These instructions are designed to socially engineer viewers into running a PowerShell command that downloads and executes a remote script, ultimately compromising their system.
Trend Research uncovered a new social engineering campaign using TikTok to deliver the Vidar and StealC information stealers... attackers are using TikTok videos that are potentially generated using AI-powered tools to socially engineer users into executing PowerShell commands under the guise of guiding them to activate legitimate software or unlock premium features.
« Ces programmes copient les cookies de connexion stockés dans le navigateur » ; « Un attaquant qui copie ce cookie et le rejoue depuis un autre appareil apparaît alors [...] comme la personne ayant déjà réussi cette vérification ».
665 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Voleur d’informations utilisé pour copier les cookies de session stockés dans les navigateurs ainsi que les mots de passe enregistrés, permettant le détournement de sessions et le contournement de l’authentification à deux facteurs.
Named as one of several infostealers identified on impacted systems that can collect login cookies, application credentials, and browser passwords, enabling theft of active Claude sessions.
An information stealer identified as capable of stealing active Claude session cookies from infected Windows computers, enabling account access without passwords and bypassing MFA and SSO.
Infostealer used to steal Claude login sessions from affected Windows computers, enabling unauthorized account access and consumption of available tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.