StealC 2.0 Unleashed: Malware Evolves with Advanced Stealth Features and Enhanced Data Theft Capabilities


# StealC Malware Evolves with Enhanced Stealth and Data Theft Capabilities

StealC, a prominent information stealer and malware downloader, has released version 2.0 with significant upgrades to its theft and stealth capabilities. Though launched in March 2025, Zscaler researchers have only recently published their comprehensive analysis of the new version, which has already seen several updates with the latest being version 2.2.4.

## Background and Evolution

First appearing on dark web markets in early 2023, StealC quickly gained popularity as a lightweight information stealer available to cybercriminals for $200 per month. Throughout 2024, it was deployed in large-scale malvertising campaigns and attacks that trapped systems in kiosk modes. Late 2024 saw StealC developers implementing methods to bypass Chrome’s ‘App-Bound Encryption’ defenses, enabling the theft and regeneration of expired cookies to hijack Google accounts.

## Key Enhancements in Version 2

The latest iteration introduces several sophisticated improvements:

– **Expanded payload delivery options** including EXE files, MSI packages, and PowerShell scripts with configurable triggering mechanisms
– **Enhanced encryption** using RC4 for code strings and command-and-control communications
– **Architectural improvements** with 64-bit system compatibility and dynamic API function resolution
– **New embedded builder** allowing operators to generate custom StealC builds with specific data theft rules
– **Telegram integration** providing real-time alerts to operators
– **Multi-monitor screenshot capability** for comprehensive victim surveillance

Interestingly, some features have been removed, including anti-VM checks and DLL execution capabilities. This may represent an effort to streamline the malware or could be temporary removals during code restructuring.

## Current Deployment Methods

Recent attacks observed by Zscaler show StealC being deployed via Amadey, another malware loader, though deployment methods vary between different criminal operators.

## Protection Recommendations

To safeguard against information-stealing malware like StealC:
– Avoid storing sensitive information in browsers
– Implement multi-factor authentication for all accounts
– Never download software from unofficial or suspicious sources

Share This Article