Infostealer
Stealc
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023.
Stealc is a Windows infostealer.
Background
Stealc is an information stealer that its likely author, Plymouth, has promoted on Russian-language underground forums and offered as a Malware-as-a-Service since January 9, 2023. By Plymouth's own account, stealc is a non-resident stealer with configurable data collection options, and its design draws on several well-known stealers: Vidar, Raccoon, Mars and Redline.
Built in C and relying on WinAPI functions, Stealc chiefly goes after data from web browsers, browser extensions and desktop cryptocurrency wallet applications, as well as other programs such as messengers and email clients. To pull sensitive browser data, it fetches 7 legitimate third-party DLLs: sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. The harvested data is then sent to its C2 server one file at a time via HTTP POST requests.
Source: Malpedia (Fraunhofer FKIE).