StealC Stealer
StealC Stealer is an information-stealing malware family distributed through multiple social-engineering and malware-delivery ecosystems. The provided reporting places it in campaigns abusing trusted platforms and user-interest lures, including bogus GitHub repositories, SEO-poisoned results, fake software and game-cheat downloads, compromised YouTube accounts in the "YouTube Ghost Network," and ClickFix-style prompts delivered via compromised WordPress sites impersonating verification or installation flows. It has been observed as one of several payloads delivered by the CastleLoader malware-as-a-service ecosystem operated by the threat actor GrayBravo, and it is also referenced in reporting that describes StealC as an improved version of Vidar Stealer. The malware is associated with Windows compromises in the cited ClickFix/WordPress activity. No direct technical indicators specific to StealC itself are provided in the content, but the surrounding delivery infrastructure includes malicious links hosted on services such as MediaFire, Dropbox, Google Drive, Google Sites, Blogger, Telegraph, and bogus GitHub repositories, as well as YouTube videos and compromised WordPress sites used to lure victims.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Execution
1 technique
Execution
Credential Access
1 technique
Credential Access
Discovery
1 technique
Discovery
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a stealer malware family distributed through bogus GitHub repositories.
A Windows stealer malware family used as an end payload in compromised WordPress ClickFix campaigns.
An information-stealing malware family referenced as an associated analytic story.
StealC Stealer is an information stealer malware distributed via the CastleLoader framework.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.