DISCARDED: Tales From the Threat Research Trenches
DISCARDED: Tales From the Threat Research Trenches

StealC Exposed: Tracking, Emulating, and Disrupting a Top Info Stealer

Show notes

Send us fan mail!

Hello to all our Cyber Pals!

Host Selena Larson is joined by Golo Mühr, Malware Reverse Engineer, X-Force Threat Intelligence and Kyle Cucci (Staff Threat Researcher, Proofpoint) to break down the joint research that helped power a major Operation Endgame disruption. 

Coordinated by Europol, the operation hit 66 domains and 296 servers tied to StealC and its close cousin Amadey, and led to the seizure of more than 25.6 million unique credentials stolen from over 385,000 compromised sites.


In this episode, Golo and Kyle take us inside the investigation:

  • How they built a custom StealC emulator to impersonate infected bots, talk to live C2 servers, and pull down real second-stage payloads
  • The tangled relationship between StealC and Amity, and how shared panels and configs let researchers cluster affiliates together
  • Why StealC sometimes delivers... more StealC (spoiler: probably not a masterplan)
  • A juicy case of "no honor among thieves" — evidence that one affiliate exploited a panel vulnerability to steal from other affiliates
  • The one confirmed instance of StealC delivering LockBit Black ransomware, caught in the wild via emulation
  • Why info stealers have become so attractive to threat actors compared to ransomware — lower risk, easier monetization, less law enforcement heat (until now)
  • What "success" actually looks like in a takedown, and why Kyle's proposed "pyramid of pain" for disruptions puts arrests at the top and infrastructure takedowns at the base

Plus: fake software downloads, sketchy YouTube game-crack links, public-private collaboration with law enforcement, and a well-earned shoutout to Proofpoint's Isaac for calling this threat over a decade ago.

Tune in for a deep dive into how threat intel teams track, emulate, and ultimately help dismantle one of the internet's most active credential-theft operations.


Resources Mentioned:


https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame


https://www.proofpoint.com/us/blog/threat-insight/threat-actors-deliver-malware-youtube-video-game-cracks



For more information about Proofpoint, check out our website.

 


Subscribe & Follow:

Stay ahead of emerging threats, and subscribe! Happy hunting!