Researchers Breach StealC Infrastructure, Access Malware Control Panels
## Cybersecurity: Analysis of StealC Malware Vulnerabilities
Cybersecurity: Analysis of StealC Malware Vulnerabilities
Recent research has highlighted vulnerabilities in the infrastructure of the StealC malware, an infostealer distributed via a Malware-as-a-Service (MaaS) model since early 2023. The malware is designed to exfiltrate cookies, passwords, and other sensitive data from compromised systems.
In the spring of 2025, significant vulnerabilities were identified in the StealC operation's infrastructure. Following the release of version 2 of StealC, researchers discovered an exploitable Cross-Site Scripting (XSS) vulnerability in the malware's control panel. This flaw enabled researchers to monitor the activities of StealC operators, collect system fingerprints, track active sessions, and steal session cookies from the malware's infrastructure.
By exploiting this vulnerability, researchers identified a threat actor known as "YouTubeTA" responsible for compromising over 5,000 machines, resulting in the theft of more than 390,000 passwords and 30 million cookies. The attack method involved hijacking legitimate YouTube channels to promote malware-laced software downloads.
The malware is designed to exfiltrate cookies, passwords, and other sensitive data from compromised systems.
Further analysis revealed that "YouTubeTA" operates as a single threat actor. Hardware fingerprinting indicated the use of an Apple M3 processor, with language settings supporting English and Russian. Timezone data pointed to a location in Eastern Europe. An IP address captured during an unprotected access session further confirmed the actor's location in Ukraine.
The breach emphasizes the weaknesses in the MaaS model, which, while facilitating widespread credential theft, also exposes threat actors to vulnerabilities. Poor security practices by StealC developers, such as the lack of httpOnly cookie protections, have allowed researchers to gain insights into the operations of multiple threat actors simultaneously.
Based on reporting by GBHackers.
