Stealc, a malware-as-a-service Windows information stealer advertised on Russian-speaking cybercrime forums in January 2023, rapidly gained criminal adoption. The malware borrows capabilities and design elements from Vidar, Raccoon, Mars, and RedLine, stealing browser credentials and cookies, cryptocurrency-wallet data, desktop-wallet files, and information from Discord, Telegram, Outlook, Steam, and Tox. Researchers observed more than 40 samples and at least 35 active command-and-control servers, with campaigns using YouTube videos and cracked-software downloads as lures.
Stealc uses RC4 and Base64 string obfuscation, dynamic API resolution, sandbox checks, staged C2 tasking, and self-deletion following exfiltration. It is part of a broader active ecosystem of Windows stealers including RedLine, MetaStealer, and Agent Tesla: RedLine dominated observed telemetry during 2022–2023, while Agent Tesla activity increased through 2024. Defenders should prioritize detection of suspicious access to browser credential stores and cryptocurrency-wallet files, as well as unsigned executables communicating with Telegram or Discord infrastructure.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
While tracking infostealer distribution infrastructure, Sekoia.io found a new malware family and assessed with high confidence that it was Stealc based on matching technical characteristics and C2 communications.
A threat actor using the handle Plymouth advertised the Stealc malware-as-a-service stealer on the Russian-speaking XSS and BHF underground forums, later promoting it through Exploit and Telegram.
MetaStealer emerged and was advertised as a RedLine-derived information stealer with additional capabilities.
The RedLine Windows information stealer debuted and was initially distributed through email. It later operated as a malware-as-a-service offering sold on underground forums.
Elastic Security created the Windows_Trojan_Stealc_df3cdc7e YARA rule to detect an x86 Stealc sample identified by SHA-256 503879c9c294cd7a2b7b13c643b93d8a8e7ae00af5b2b56fcbb90e6c096f40d6. The rule uses a specified byte pattern to scan Windows files and memory.
Elastic telemetry covering 2023 to 2024 showed a notable increase in Agent Tesla activity, with RedLine, Stealc, and Vidar following it in observed prevalence.
Sekoia.io observed several dozen Stealc samples and more than 40 associated C2 servers, including 35 active C2 servers identified with high confidence, indicating rapid adoption by cybercriminals.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 142 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
docs.elastic.co
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceelastic.co
Open sourceblog.sekoia.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.