typeentityconfidencehighcreated2026-07-26updated2026-07-26infostealermalware-familyc2exfiltrationcompiler

Stealc

Commodity C++ infostealer sold as malware-as-a-service. Targets browser credentials, cryptocurrency wallets, and system information. Exfiltrates via HTTPS C2 using WINHTTP. Often delivered by AutoIt or NSIS droppers.

Build / RE

  • Language: C++ (MSVC, typically VS 2019–2022)
  • Packing: None — payload is a plain PE32 or PE32+
  • Anti-analysis: Minimal. No VM/debug checks in the payload itself; evasion is usually handled by the dropper
  • Signing: Unsigned
  • RTTI: Full MSVC RTTI present (Type Descriptor, Class Hierarchy Descriptor, Complete Object Locator)
  • POGO: Profile-Guided Optimization debug directory common (IMAGE_DEBUG_TYPE_POGO)
  • GuardCF: Enabled in recent builds
  • SQLite: Statically linked SQLite 3.x engine for local credential/database staging

Deploy / ATT&CK

  • T1056.001 — Input Capture: Keylogging (keyboard.txt, keylogall.txt in %TEMP%)
  • T1555 — Credentials from Password Stores (Chromium extension local storage paths)
  • T1649 — Steal Crypto Wallet (BIP-39 seed-phrase regex; ledger strings)
  • T1559 — Inter-Process Communication via named pipe (\\.\\pipe\\ssstealer)
  • T1071.001 — Application Layer Protocol: Web (WINHTTP HTTPS C2)
  • T1041 — Exfiltration Over C2
  • T1486 — Data Encrypted for Impact (CryptEncrypt / CryptDecrypt via ADVAPI32)
  • T1132 — Data Encoding (CryptBinaryToStringA Base64)
  • T1003 — OS Credential Dumping (GetUserNameW + SQLite aggregation)

Capabilities

  • keylogging-temp-file-staging
  • chromium-extension-local-storage-theft
  • seed-phrase-regex-harvest
  • named-pipe-ipc-ssstealer
  • winhttp-https-c2
  • sqlite-local-credential-store
  • advapi32-crypt-encrypt-exfil
  • base64-cryptbinarytostring-encoding

Known Infrastructure

Domain / Endpoint Role Sample
sport-zb.osptoe.cn Primary HTTPS C2 cace58e8
cgres.oss-cn-hongkong.aliyuncs.com Alternate exfil (Aliyun OSS) cace58e8

Attribution Notes

  • The ssstealer pipe name is a high-confidence family fingerprint
  • xp.dll init finish and rkbf,3 strings are builder/plugin markers observed across multiple Stealc samples
  • Builder-generated fake company names (e.g., Longrun Financial Group Limited) masquerade as legitimate software

Siblings in Corpus

  • cace58e8 — C++ MSVC 14.43 PE32, Mar 2026 build. Primary sample for this entity page. Static-only analysis.
  • 43998b11d — Go PE64+ with quiverquant.com/WE1 self-signed cert, OpenCTI co-labelled stealc and vidar. Static analysis resolves to acrstealer cluster, not Stealc. See /intel/analyses/43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002.html. Contested attribution.