HomeSecurityStealC info-stealer malware becomes even more dangerous

StealC info-stealer malware becomes even more dangerous

The developers of StealC — a popular tool used for data theft (info-stealer malware) and malware distribution — have released its second major release, which includes significant improvements in terms of evasion of detection and efficiency in information theft.

StealC info-stealer malware

The creators of StealC also rent the malware to other hackers. The most recent version of StealC was offered to cybercriminals in March 2025. However, only recently did Zscaler experts publish a detailed analysis .

Additionally, in the weeks following the release of the new version, several smaller updates were added that fixed bugs and introduced new features. The most recent of these is version 2.2.4.

See also: Hackers use Eye Pyramid Tool to develop malware

StealC is a “lightweight” malware that aims to steal data and gained particular popularity on the dark web in early 2023. Hackers could gain access to it by paying a subscription ($200 per month).

By the end of 2024, StealC was confirmed to be in active development. Its creators had even added a mechanism that bypassed 's Chrome cookie protection measures ("App-Bound Encryption"), allowing expired cookies to be "restored" to access Google accounts.

What's new in the latest version of StealC?

According to Zscaler, the second version of StealC and its subsequent variants bring several upgrades, the most significant of which are:

  • Significant improvements to the way the malicious payload is delivered, with support for EXE executables, MSI packages, and PowerShell scripts, while its activation can be customized as needed.
  • RC4 encryption has been added for both code strings and communications with command and control (C2) servers, with random parameters in C2 responses to make them more difficult to detect.
  • The malware's architecture and execution have been improved, with new payloads being compiled specifically for 64-bit systems . In addition, a self-deletion process has been added after the attack is complete.
  • A new, built-in tool allows operators to build variants of StealC, based on templates and customized data interception rules.
  • It is now possible to send real-time notifications via Telegram, to immediately inform cybercriminals.
  • A function has also been added to take screenshots of the victim's desktop, with support for systems with multiple monitors.

See also: Tsunami malware features Miners and Credential Stealers

However, according to the researchers, some previous features appear to have been removed (e.g. checks for virtual environments (anti-VM) and the ability to download and execute DLL libraries).

StealC info-stealer malware becomes even more dangerous

This may indicate an attempt to make the malware simpler and more flexible, or it may be a side effect of extensive code changes. It is possible that these features will return in future, improved versions.

According to Zscaler's latest analysis, StealC malware is often distributed via Amadey, a separate malware loader, although different operators may choose different distribution methods or attack strategies.

To protect your personal data from such threats, it is recommended that you do not store sensitive information in your browser, enable multi-factor authentication for the security of your accounts, and avoid downloading pirated or untrusted software.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

See also: New DslogdRAT malware is distributed via vulnerability in Ivanti Connect Secure

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS