logo

I StealC You: Tracking the Rapid Changes To StealC

ID: 74179dd2-2af8-5df8-8eea-fa03eab0e9be

STIX ID: report--74179dd2-2af8-5df8-8eea-fa03eab0e9be

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-05-27

Date Updated: 2026-05-01

...
...

This report presents a technical analysis of StealC V2, an actively developed information-stealer that uses Themida packing, RC4-encrypted strings and C2 traffic, and a control-panel-embedded builder; it details features such as browser and wallet theft, screenshot capture, EXE/MSI/PowerShell payload execution, C2 JSON protocol and opcodes, RC4 key handling, and builder/panel behaviors (including loader rules, Telegram integration, and update packaging).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.