#stealc — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #stealc, aggregated by home.social.
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
StealC and Amadey: Breaking down infostealers and the cybercrime services thatdeliver them - https://www.redpacketsecurity.com/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-thatdeliver-them/
#threatintel
#infostealers
#StealC
#Amadey
#malware-as-a-service
#cybercrime-economy -
StealC and Amadey: Breaking down infostealers and the cybercrime services thatdeliver them - https://www.redpacketsecurity.com/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-thatdeliver-them/
#threatintel
#infostealers
#StealC
#Amadey
#malware-as-a-service
#cybercrime-economy -
📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
Listen or Read: https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/
-
📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
Listen or Read: https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/
-
Lees tip -> Politie haalt malware StealC en Amadey offline in Operatie Endgame | Bij een internationale actie tegen infostealers zijn criminele servers offline gehaald. Politie vond ruim 24 miljoen logingegevens van zeker 384.000 besmette systemen. | #ransomware #politie #infostealers #Europol #cybercrime #StealC #malware #Eurojust #OperatieEndgame #Amadey |
https://hbpmedia.nl/politie-haalt-malware-stealc-en-amadey-offline-in-operatie-endgame/
-
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
#Stealc #Amadey
https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/ -
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
#Stealc #Amadey
https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/ -
https://app.any.run/tasks/9cd9a0f0-bf6f-4a23-9bf0-4d804f816b07
c2: https:// pas. canamrent .com/
-
https://app.any.run/tasks/9cd9a0f0-bf6f-4a23-9bf0-4d804f816b07
c2: https:// pas. canamrent .com/
-
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
#SmartApeSG #RemcosRAT #Stealc #SecTopRAT
https://isc.sans.edu/diary/32826 -
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
#SmartApeSG #RemcosRAT #Stealc #SecTopRAT
https://isc.sans.edu/diary/32826 -
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826
-
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826
-
Middle East Conflict Fuels Opportunistic Cyber Attacks
#LOTUSLITE #Stealc
https://www.zscaler.com/blogs/security-research/middle-east-conflict-fuels-opportunistic-cyber-attacks -
Middle East Conflict Fuels Opportunistic Cyber Attacks
#LOTUSLITE #Stealc
https://www.zscaler.com/blogs/security-research/middle-east-conflict-fuels-opportunistic-cyber-attacks -
https://winbuzzer.com/2026/02/19/fake-captcha-trick-installs-stealc-on-windows-pcs-xcxwbn/
Fake CAPTCHA Trick Installs StealC on Windows PCs
#Windows #Security #Cybersecurity #StealC #Malware #Cybercrime #Hackers #WindowsSecurity #PowerShell #Scams #DataTheft #ThreatActors #CyberThreats #Cyberattacks #MicrosoftOutlook #Steam #Cryptocurrency
-
https://winbuzzer.com/2026/02/19/fake-captcha-trick-installs-stealc-on-windows-pcs-xcxwbn/
Fake CAPTCHA Trick Installs StealC on Windows PCs
#Windows #Security #Cybersecurity #StealC #Malware #Cybercrime #Hackers #WindowsSecurity #PowerShell #Scams #DataTheft #ThreatActors #CyberThreats #Cyberattacks #MicrosoftOutlook #Steam #Cryptocurrency
-
DocSend.exe signed "Taiyuan Yuqianhan Network Technology Co., Ltd."; Certificate reported
b409adb785f58f1de1cdf12e5c7c51a2C2: 185.174.133.12
https://tria[.]ge/260211-2qa1ascw9d/behavioral1
#StealCh/t @malwrhunterteam
-
Badacze zhakowali panel administracyjny infostealera StealC. Wszystko przez XSS i błędy w konfiguracji
Malware StealC jest dobrze znany zarówno w środowisku cyberprzestępców jak i badaczy bezpieczeństwa. Popularność zyskał przede wszystkim za sprawą niskiego progu wejścia dla atakujących oraz wysoką skutecznością działania. Jest oferowany w modelu Malware-as-a-Service (MaaS). Charakteryzuje się masowym wykradaniem ciasteczek sesyjnych (pliki cookie), kradzieżą danych z portfeli kryptowalutowych oraz wsparciem dla...
#WBiegu #Clickfix #Infostealer #Malware #Stealc #XSS #Youtube
-
Badacze zhakowali panel administracyjny infostealera StealC. Wszystko przez XSS i błędy w konfiguracji
Malware StealC jest dobrze znany zarówno w środowisku cyberprzestępców jak i badaczy bezpieczeństwa. Popularność zyskał przede wszystkim za sprawą niskiego progu wejścia dla atakujących oraz wysoką skutecznością działania. Jest oferowany w modelu Malware-as-a-Service (MaaS). Charakteryzuje się masowym wykradaniem ciasteczek sesyjnych (pliki cookie), kradzieżą danych z portfeli kryptowalutowych oraz wsparciem dla...
#WBiegu #Clickfix #Infostealer #Malware #Stealc #XSS #Youtube
-
The other day I was thinking, when will infostealers start collecting information from "AI" browsers.
Today noticed that StealC has posted an update, where they added a feature of collecting Sigma AI Browser data.
''Sigma AI Browser is an AI‑first agentic browser that combines an AI agent, deep research, and AI tools to help you navigate, create, and'' sloooop
Anyways, left to find some time and energy to look for some stealc logs and see if it syphons some more juicy data from "ai" browsers.
-
The other day I was thinking, when will infostealers start collecting information from "AI" browsers.
Today noticed that StealC has posted an update, where they added a feature of collecting Sigma AI Browser data.
''Sigma AI Browser is an AI‑first agentic browser that combines an AI agent, deep research, and AI tools to help you navigate, create, and'' sloooop
Anyways, left to find some time and energy to look for some stealc logs and see if it syphons some more juicy data from "ai" browsers.
-
UNO reverse card: stealing cookies from cookie stealers
#Stealc
https://www.cyberark.com/resources/threat-research-blog/uno-reverse-card-stealing-cookies-from-cookie-stealers -
UNO reverse card: stealing cookies from cookie stealers
#Stealc
https://www.cyberark.com/resources/threat-research-blog/uno-reverse-card-stealing-cookies-from-cookie-stealers -
Mentioned Malware Families: Stealc, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2Aliases provided by Malpedia.
-
Here's the full infection chain:
198.211.110.107:79finger connects to finger[.]cloudyape[.]com172.67.190.68:80curl triescloudyape[.]com/uvey.php?holt=2but server responds with '301 Moved Permanently' and redirects to HTTPS172.67.190.68:443dropper download172.67.190.68:80curl getscloudyape[.]com/uvey.php?holt=1server redirects to HTTPS172.67.190.68:443dropper download170.130.165.201:80Download offile4.bin(#StealC) with fakeGoogeBotuser agent170.130.165.201:80#StealC v2 C2 / exfiltration170.130.55.38:80#CastleLoader traffic194.76.227.242:9999#CastleRAT C2 traffic
-
This #StealC and #CastleRAT infection starts with a #ClickFix attack using finger to download commands from finger[.]cloudyape[.]com