Researchers detailed the StealC infostealer as a growing malware family sold on underground forums and operated through self-hosted PHP-based panels, with public and customized private variants reportedly available to customers. Reverse-engineering reports show StealC using anti-analysis checks, dynamic API resolution, and layered string protection including RC4+Base64 and XOR decryption, while packed samples used the pkr_ce1a loader with TEA-based decryption and anti-emulation logic. Analysts also published tooling and detection content, including YARA coverage, IDA and Binary Ninja automation, and configuration extraction methods that help recover embedded indicators from samples.
The malware was shown stealing browser credentials, application logins, cryptocurrency wallet data, system information, plugins, and selected files before exfiltrating the data over HTTP in multipart requests. Multiple analyses tied samples to command-and-control infrastructure including 185.172.128.59 serving ISetup8.exe, 185.172.128.150 with the path /b7d0cfdb1d966bdd/c698e1bc8a2f5e6d.php, and 94.131.107.238 with /3aa13fff14e398a1.php; one observed sample also downloaded and executed a Laplas Clipper as a next-stage payload. The combined findings indicate that StealC remains an adaptable credential-theft platform with evolving packing, configurable infrastructure, and support for follow-on malware delivery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Lexfo's later analysis identified a final-stage sample as StealC via a strong Malpedia YARA match and recovered decoded network indicators including 185.172.128.150, /b7d0cfdb1d966bdd/, and c698e1bc8a2f5e6d.php.
Lexfo published Part 2 of its StealC analysis, showing that an embedded Stage 2 PE loader downloaded and executed syncUpd.exe from attacker-controlled infrastructure. The research recovered additional IOCs including 185.172.128.90, 185.172.128.228, and 185.172.128.59, and documented unpacking of the Stage 3 sample after bypassing anti-emulation checks.
Lexfo analyzed a StealC-family Windows sample and identified its first-stage loader as packed with pkr_ce1a, documenting TEA-based decryption, anti-emulation behavior, and infrastructure tied to ISetup8.exe and 185.172.128.59.
Lexfo reported that the analyzed StealC sample with SHA-256 c173cfcb0adfa3013a398638789bf4350601cce0e1c55a456d98311543062f82 was first seen on MalwareBazaar at 07:13:32 UTC.
An interview with the StealC developer described the malware's C-language codebase, PHP admin panel, self-hosted customer model, CIS/Ukraine exclusion logic, and private variants for selected clients.
A GitHub repository published an IDA Pro Python script to decode Base64- and RC4-obfuscated StealC strings and annotate recovered plaintext during reverse engineering.
A public GitHub notebook demonstrated extraction and RC4 decryption of StealC configuration data, recovering the IP address 94.131.107.238 and PHP path /3aa13fff14e398a1.php from a sample.
The developer stated that StealC started being sold publicly in January 2023. Lexfo also described StealC as a Malware-as-a-Service active since January 2023.
In an interview, the malware's developer said StealC began closed testing in summer 2022 and that about 40 people participated before public sale.
Sekoia reported that StealC was advertised by the Plymouth threat actor on the XSS, Exploit, and BHF underground forums, marking its emergence in criminal marketplaces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcemaxchertin.github.io
Open sourcegithub.com
Open sourceblog.lexfo.fr
Open sourceg0njxa.medium.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceblog.sekoia.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.