Stealc
Commodity C++ infostealer sold as malware-as-a-service. Targets browser credentials, cryptocurrency wallets, and system information. Exfiltrates via HTTPS C2 using WINHTTP. Often delivered by AutoIt or NSIS droppers.
Build / RE
- Language: C++ (MSVC, typically VS 2019–2022)
- Packing: None — payload is a plain PE32 or PE32+
- Anti-analysis: Minimal. No VM/debug checks in the payload itself; evasion is usually handled by the dropper
- Signing: Unsigned
- RTTI: Full MSVC RTTI present (Type Descriptor, Class Hierarchy Descriptor, Complete Object Locator)
- POGO: Profile-Guided Optimization debug directory common (
IMAGE_DEBUG_TYPE_POGO) - GuardCF: Enabled in recent builds
- SQLite: Statically linked SQLite 3.x engine for local credential/database staging
Deploy / ATT&CK
- T1056.001 — Input Capture: Keylogging (
keyboard.txt,keylogall.txtin%TEMP%) - T1555 — Credentials from Password Stores (Chromium extension local storage paths)
- T1649 — Steal Crypto Wallet (BIP-39 seed-phrase regex; ledger strings)
- T1559 — Inter-Process Communication via named pipe (
\\.\\pipe\\ssstealer) - T1071.001 — Application Layer Protocol: Web (WINHTTP HTTPS C2)
- T1041 — Exfiltration Over C2
- T1486 — Data Encrypted for Impact (CryptEncrypt / CryptDecrypt via ADVAPI32)
- T1132 — Data Encoding (CryptBinaryToStringA Base64)
- T1003 — OS Credential Dumping (GetUserNameW + SQLite aggregation)
Capabilities
keylogging-temp-file-stagingchromium-extension-local-storage-theftseed-phrase-regex-harvestnamed-pipe-ipc-ssstealerwinhttp-https-c2sqlite-local-credential-storeadvapi32-crypt-encrypt-exfilbase64-cryptbinarytostring-encoding
Known Infrastructure
| Domain / Endpoint | Role | Sample |
|---|---|---|
sport-zb.osptoe.cn |
Primary HTTPS C2 | cace58e8 |
cgres.oss-cn-hongkong.aliyuncs.com |
Alternate exfil (Aliyun OSS) | cace58e8 |
Attribution Notes
- The
ssstealerpipe name is a high-confidence family fingerprint xp.dll init finishandrkbf,3strings are builder/plugin markers observed across multiple Stealc samples- Builder-generated fake company names (e.g.,
Longrun Financial Group Limited) masquerade as legitimate software
Siblings in Corpus
- cace58e8 — C++ MSVC 14.43 PE32, Mar 2026 build. Primary sample for this entity page. Static-only analysis.
- 43998b11d — Go PE64+ with
quiverquant.com/WE1self-signed cert, OpenCTI co-labelledstealcandvidar. Static analysis resolves to acrstealer cluster, not Stealc. See /intel/analyses/43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002.html. Contested attribution.