Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Researchers Gain Access to StealC Malware Command-and-Control Systems

Security researchers have successfully identified vulnerabilities within the StealC malware infrastructure. These vulnerabilities allowed access to operator control panels and revealed the identity of a threat actor through their own stolen session…

Security researchers have successfully identified vulnerabilities within the StealC malware infrastructure. These vulnerabilities allowed access to operator control panels and revealed the identity of a threat actor through their own stolen session cookies.

XSS Vulnerability Exposes StealC Operators

StealC is an information-stealing malware operating under a Malware-as-a-Service model since early 2023. A cross-site scripting (XSS) vulnerability in its web panel was discovered by researchers following a code leak in spring 2025. This vulnerability enabled researchers at CyberArk Labs to gather system data, monitor sessions, and capture authentication cookies from the system designed to steal them.

The operators of StealC, who focus on cookie theft, failed to implement fundamental security measures, such as the httpOnly flag, which would have prevented cookie hijacking through XSS attacks.

Access to the panel allowed researchers to track an operator identified as "YouTubeTA," who maintained over 5,000 infection logs containing 390,000 stolen passwords and 30 million cookies. Screenshots captured by the malware indicated that victims were looking for cracked versions of Adobe software on YouTube, suggesting that legitimate YouTube channels with established subscriber bases were compromised to distribute StealC.

Security researchers have successfully identified vulnerabilities within the StealC malware infrastructure.
Lucas Norwood · Thehackingpost

The configuration of the operator's panel included specific markers for studio.youtube.com credentials, indicating a strategy to hijack content creator accounts and extend malware distribution networks. Panel fingerprinting identified the operator as using an Apple M3 processor, with consistent hardware signatures across all sessions, according to CyberArk Labs.

Language preferences indicated support for English and Russian, while timezone data suggested GMT+0300 (Eastern European Summer Time). A significant operational security failure occurred when the operator briefly connected without VPN protection, revealing an IP address associated with a Ukrainian ISP, TRK Cable TV.

Advertisement

This breach underscores how vulnerabilities in Malware-as-a-Service supply chains can expose both infrastructure weaknesses and operator identities to security researchers.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories