This new malware has emerged from the dark web and is after your data


Experts have warned of a new information-stealing malware has been observed circulating around the dark web as it looks to gather new customers and victims alike.
Cybersecurity researchers from SEKOIA came across multiple ads, on different underground forums and Telegram groups promoting a new infostealer called Stealc.
Apparently, Stealc is not built from scratch, but is rather an upgrade to other, more popular infostealers, such as Vidar, Racoon, Mars, and Redline Stealer, having been first spotted in January 2023 but then gaining more traction the following month.
Weekly updates
Stealc was built, and is being advertised, by a threat actor going by the name “Plymouth”. It is currently at version 1.3.0, and it seems to be getting new tweaks and upgrades at least once a week.
Some of the newly added features include a C2 URL randomizer, and improved logs searching and sorting system. Stealc was also seen sparing people from Ukraine.
After further analyzing a sample of the infostealer, SEKOIA uncovered that it uses legitimate third-party DLLs, that it’s written C and abuses Windows API functions, that it’s lightweight (only 80KB), that it obfuscates most of its strings with RC4 and base64, and that it exfiltrates stolen files automatically (requiring no action from the threat actor).
SEKOIA has also found Stealc to be able to steal data from 22 web browsers, 75 plugins, and 25 desktop wallets.
Besides advertising it on the dark web, Plymouth was also busy deploying it to target endpoints (opens in new tab). One of the ways they do it is by creating fake YouTube tutorials on how to crack software, and providing a link in the description which, instead of the advertised crack, deploys the infostealer.
So far, more than 40 C2 servers were discovered, leading the researchers to conclude Stealc is growing quite popular. The popularity, they speculate, comes from the fact that crooks that can access the admin panel can easily generate new stealer samples, thus increasing its range.
SEKOIA believes Stealc can become quite popular as it can be adopted by low-level hackers, as well.
Via: BleepingComputer (opens in new tab)
Audio player loading… Experts have warned of a new information-stealing malware has been observed circulating around the dark web as it looks to gather new customers and victims alike. Cybersecurity researchers from SEKOIA came across multiple ads, on different underground forums and Telegram groups promoting a new infostealer called Stealc.…
Recent Posts
- Over a million clinical records exposed in data breach
- Rabbit AI’s new tool can control your Android phones, but I’m not sure how I feel about letting it control my smartphone
- Everything missing from the iPhone 16e, including MagSafe and Photographic Styles
- Reddit is reportedly experiencing some outages
- Google may be close to launching YouTube Premium Lite
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010