logo

StealC hackers hacked as researchers hijack malware control panels

ID: d2856a87-3d61-5881-a96c-6db3bf591c91

STIX ID: report--d2856a87-3d61-5881-a96c-6db3bf591c91

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CyberArk researchers discovered an XSS vulnerability in the web control panel used by StealC infostealer operators, allowing them to hijack sessions, steal session cookies, and collect operator fingerprints; the report details an active StealC campaign ('YouTubeTA') that amassed over 5,000 victim logs, ~390,000 stolen passwords and ~30 million cookies, and exposes operational metadata including a real IP tied to a Ukrainian ISP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.