logo

Stealc Infostealer: Reverse Engineering

ID: 2c6a1f32-23eb-5d13-8050-ff2ccb14c2cc

STIX ID: report--2c6a1f32-23eb-5d13-8050-ff2ccb14c2cc

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2023-02-27

Date Updated: 2026-07-20

...
...

This Sekoia technical analysis details the Stealc information stealer—an infostealer resembling Vidar and Raccoon—covering its anti-analysis tricks, RC4+base64 string obfuscation, dynamic API resolution, host and environment checks, extensive targeting of browsers/wallets/plugins and file grabber functionality, HTTP-based C2 with base64-encoded POST forms, DLL download/loading for data access, next-stage payload capability (e.g., a Laplas Clipper), trace removal behavior, and provides SHA-256 samples, C2 patterns, and scripts to extract/deobfuscate configuration and strings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.