Infostealer
StealC
Infostealer
28 detections found
Also known as: Stealc, StealC V2, Stealc Stealer
StealC is a lightweight (~80KB) Windows information stealer that emerged on Russian-speaking underground forums (XSS, BHF) in January 2023, sold as malware-as-a-service by an actor using the handle "Plymouth" and modeled on Vidar, Raccoon, Mars, and RedLine. It is delivered via cracked-software sites and drive-by/phishing lures, and its file-grabber and stealer modules target credentials, cookies, and autofill data from 20+ browsers, 75+ browser extensions/crypto wallets, and apps like Discord, Telegram, and Steam. No law-enforcement disruption has been reported; the family remains actively maintained, with a StealC V2 update in 2024-2025 adding stealth and expanded data-theft features.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.