Researchers identified SvcStealer as a new information-stealing malware family distributed through spear-phishing attachments and active since early 2025. Written in Microsoft Visual C++, the malware collects system details, installed software inventories, browser data, saved credentials, cryptocurrency wallet information, messaging app data, screenshots, and selected files before compressing the haul and exfiltrating it over HTTP POST traffic on port 80 to command-and-control infrastructure designed to blend in with normal web activity.
Analysis linked the malware to infrastructure including 176.113.115.149, 185.81.68.156, and the path /svcstealer/get.php, while reporting that some associated domains were unreachable during investigation. SvcStealer also uses anti-analysis and evasion techniques such as killing Task Manager and process inspection tools, enforcing a single running instance using a victim identifier derived from the host volume serial number, deleting traces after exfiltration, and downloading additional payloads for follow-on compromise; MalwareBazaar has tracked 125 related samples, with sightings extending into August 2026.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Broadcom published a protection bulletin on SVCStealer describing its C++ infostealer behavior, including theft of credentials, browser data, cryptocurrency wallets, screenshots, messaging and VPN app data, and ZIP-based exfiltration to C2 servers. The bulletin also stated that Symantec and VMware Carbon Black detect or block the threat through behavioral, file-based, machine-learning, network-based, and web-based protections.
MalwareBazaar's SVCStealer signature entry shows its first seen alert timestamp on 2025-02-01 15:32:42 UTC, marking the earliest sample observation in that database entry.
Researchers reported that the SvcStealer information-stealing malware family was first observed in January 2025. Rewterz described it as newly identified, and Seqrite placed campaign activity at the end of that month.
The MalwareBazaar SVCStealer entry lists a last seen timestamp of 2026-08-10 15:00:23 UTC and reports 125 associated malware samples in the database.
Rewterz published a threat advisory describing SvcStealer's credential, browser, and cryptocurrency theft capabilities, HTTP POST exfiltration, and evasion techniques. The advisory also disclosed active indicators of compromise including IPs 185.81.68.156 and 176.113.115.149 and multiple file hashes.
Seqrite released a technical analysis of SvcStealer, detailing its spearphishing delivery, data theft and exfiltration behavior, C2 infrastructure, and follow-on payload capability. The report also published detections including TrojanSpy.SvcStealer.S35070558 and TjnSpy.SvcStealer.S35070557.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
bazaar.abuse.ch
Open sourcerewterz.com
Open sourcebroadcom.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.