Nov. 29, 2023, 6:46 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

We continue to publish our analysis report of Stealc, an information stealer promoted by its supposed developer Plymouth on Russian-language underground forums and sold as malware as a service since January 9, 2023.



In this part we are analyse exfiltration system information and downloader logic of stealer.


Download Browsers Configurations:


inside sub_0x403D5F() → renamed to mw_Download_1(), Stealc again will ask C2 to feed it with some configuration to be used in stealth behavior, it will do the same steps done …

analysis browsers continue developer download downloader exfiltration forums information information stealer january language logic malware malware analysis report russian russian-language service stealc stealc stealer stealer system underground

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States