StealC is a prominent malware-as-a-service in the growing ecosystem of information stealers. As identity continues to be a rich target for threat actors, the information stealer economy poses a significant and growing threat to organisations and private individuals alike. IBM X-Force and Proofpoint recently participated in joint collective action against these disruptions.
The disruption was carried out in June 2026 as part of Operation Endgame by law enforcement agencies and private partners.
On 24 June 2026, law enforcement and private partners announced a disruption action against StealC, targeting 66 domains and 296 servers associated with both Amadey and StealC. Microsoft’s Digital Crimes Unit filed a lawsuit against multiple alleged enablers involved and took down infrastructure associated with the malware.
What is StealC?
StealC is a popular infostealer malware, which has been sold as a malware-as-a-service (MaaS) since January 2023. Clients of this service, also called affiliates, use a control panel to build and distribute malware that steals sensitive data from victims. The stolen data is processed and stored on the panel server, which affiliates can use to manage active infections, distribute secondary payloads, and update their configurations.
In March 2025, developers released StealC version 2. The latest build, v2.22.0, was released on May 26, 2026. The malware targets a wide range of sensitive data, including browser credentials, cookies, and payment card data; messages and accounts from email and communications platforms, including Outlook, Telegram, and Discord; gaming platform credentials; credentials from VPN and file transfer tools; and cryptocurrency wallets.
The stolen data may then be leveraged by the affiliates directly or sold on underground markets and has frequently been leveraged to launch further attacks against organisations, resulting in significant damage.
Emulating StealC clients
To track the operations, infrastructure, and payloads of the StealC operators, Proofpoint and X-Force built StealC bot emulation capabilities and designed several tools that emulate the network activity of a normal StealC infection using StealC samples from internal data sources, as well as external data sources such as VirusTotal and sharing partners. Each StealC sample was fed into malware sandboxes , and configuration extraction scripts were executed on the malware, allowing us to read, process, and store configs.
During the timeframe of our emulation operations, we observed many malware families (payloads) being delivered to systems infected with StealC. In some cases, the StealC client was delivered only one payload, such as another stealer or a remote access trojan (RAT). In many cases, the StealC client received another loader malware, which subsequently downloaded the final payload. One notable example is a StealC client downloading XTinyLoader, which, in turn, downloaded a LockBit Black ransomware payload. A ransomware payload was an edge case in our research, but these complex malware delivery chains were common.
Conclusion
The latest disruption effort marks another step in the broader series of Operation Endgame initiatives targeting the cybercrime ecosystem and the services that sustain it. By gathering intelligence and monitoring malicious infrastructure, X‑Force and Proofpoint provided key support to law enforcement, the Microsoft Digital Crimes Unit, and other private‑sector partners. These strong collaborations demonstrate how unified action can meaningfully weaken cybercriminal operations.
Proofpoint’s mission is to provide the best human-centric protection for our customers against advanced threats. Whenever it is possible and appropriate to do so, and as is the case with Operation Endgame, Proofpoint uses its team’s knowledge and skills to help protect a wider audience against widespread malware threats. Proofpoint was proud to assist in the law enforcement investigations into StealC activity.
Image Credit: Proofpoint
Source: Tahawul Tech

