StealC is an infostealer malware family that steals credentials and other sensitive data from infected systems.
StealC is a malware family tracked across 28 threat clusters and 68 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity July 21, 2026.
StealC is an infostealer malware family that steals credentials and other sensitive data from infected systems. Recent reporting links its distribution to malicious Blender 3D model files, highlighting a novel delivery vector that targets users in gaming and 3D asset ecosystems. Its prominence in gaming-targeted infostealer campaigns underscores its significance as a threat vector and a signal of evolving cybercrime tactics.
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
A new wave of scams utilizing fake CAPTCHA prompts has emerged, allowing attackers to install malware without traditional download methods. Known as 'ClickFix,' this tactic tricks users into executing malicious scripts…
Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…
The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, has been observed delivering multiple remote access trojans (RATs) including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2) through a social…
In early 2026, Darktrace identified malicious activities linked to Hola VPN, a peer-to-peer VPN service. The exploitation involved devices acting as routing nodes, leading to lateral movement and command-and-control…
On World Password Day 2026, experts highlight that traditional password security measures are inadequate against modern threats. Infostealer malware, such as LummaC2 and RedLine, now operates in a…
The AgentBaiting campaign has emerged as a significant threat, utilizing 800 fake AI Skills and Model Context Protocol (MCP) servers to deliver SmartLoader malware. This operation leverages trusted GitHub projects and…
Kaspersky Digital Footprint Intelligence's recent study reveals that over one-third of infostealer infections originate from users executing files directly from temporary browser folders. An analysis of 5 million…
StealC is an infostealer malware family that steals credentials and other sensitive data from infected systems.
The most recent intelligence report mentioning StealC on ThreatCluster is dated July 21, 2026. Activity was first observed October 28, 2025, giving a tracked span from then to July 21, 2026.
Across ThreatCluster reporting, StealC most frequently co-occurs with Evil Corp, Hanemoney, SmartApeSG, ZPHP, Botnet, among 12 tracked related entities.
The most significant recent cluster is “Operation Endgame Disrupts Evil Corp's SocGholish Malware Network” (67 articles · Updated June 18, 2026). StealC appears across 28 threat clusters in total, listed above with sources.
StealC appears in 68 intelligence report mentions across 28 deduplicated threat clusters, aggregated from 17,000+ monitored sources.