{"id":9949,"date":"2026-01-17T10:04:17","date_gmt":"2026-01-17T10:04:17","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/17\/researchers-gain-access-to-stealc-malware-command-and-control-systems\/"},"modified":"2026-01-17T10:04:17","modified_gmt":"2026-01-17T10:04:17","slug":"researchers-gain-access-to-stealc-malware-command-and-control-systems","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/17\/researchers-gain-access-to-stealc-malware-command-and-control-systems\/","title":{"rendered":"Researchers Gain Access to StealC Malware Command-and-Control Systems"},"content":{"rendered":"<p>    Researchers Gain Access to StealC Malware Command-and-Control Systems<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor\u2019s identity through their own <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-evilginx\/\" target=\"_blank\" rel=\"noreferrer noopener\">stolen session cookies<\/a>. <\/p>\n<p>The breach highlights critical security failures in criminal operations built around credential theft.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-xss-vulnerability-exposes-stealc-operators\"><strong>XSS Vulnerability Exposes StealC Operators<\/strong><\/h2>\n<p>StealC, an information-stealing malware operating under a <a href=\"https:\/\/cybersecuritynews.com\/new-ghostsocks-malware-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">Malware-as-a-Service<\/a> model since early 2023, faced a significant setback when researchers discovered a cross-site scripting (XSS) vulnerability in its web panel following a code leak in spring 2025. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" height=\"485\" width=\"1024\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-58-1024x485.png?resize=1024%2C485&#038;ssl=1\" alt=\"StealC build page with example build called \u201cYouTubeNew.\u201d\" class=\"wp-image-175190\"><figcaption class=\"wp-element-caption\">StealC build page with example build called \u201cYouTubeNew\u201d<\/figcaption><\/figure>\n<p>By exploiting this flaw, CyberArk Labs collected system fingerprints, monitored active sessions, and captured authentication cookies from the infrastructure designed to steal them. <\/p>\n<p>The irony proved significant: operators specializing in cookie theft failed to implement basic security features, such as the httpOnly flag, that would have prevented cookie hijacking via XSS attacks.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" height=\"387\" width=\"1024\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-59-1024x387.png?resize=1024%2C387&#038;ssl=1\" alt=\" YouTubeTA\u2019s StealC web panel.\" class=\"wp-image-175192\"><figcaption class=\"wp-element-caption\">\u00a0YouTubeTA\u2019s StealC web panel<\/figcaption><\/figure>\n<p>Through panel access, researchers tracked a single operator designated \u201cYouTubeTA\u201d (YouTube Threat Actor) who maintained over 5,000 infection logs containing 390,000 stolen passwords and 30 million cookies. <\/p>\n<p>Screenshots captured by the malware showed victims searching for cracked versions of<a href=\"https:\/\/cybersecuritynews.com\/adobe-photoshop-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Adobe Photoshop<\/a> and After Effects on YouTube, suggesting that YouTubeTA compromised legitimate YouTube channels with established subscriber bases to distribute StealC. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-60.png?ssl=1\" alt=\"Likely clickfix page used to install StealC\" class=\"wp-image-175193\"><figcaption class=\"wp-element-caption\">Likely clickfix page used to install StealC<\/figcaption><\/figure>\n<\/div>\n<p>The operator\u2019s panel configuration included specific markers for studio.youtube.com credentials, indicating a strategy to hijack content creator accounts and expand malware distribution networks.<\/p>\n<p>Panel fingerprinting identified YouTubeTA as a single operator using an Apple M3 processor, with consistent hardware signatures across all sessions, as <a href=\"https:\/\/www.cyberark.com\/resources\/threat-research-blog\/uno-reverse-card-stealing-cookies-from-cookie-stealers\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported <\/a>by CyberArk Labs . <\/p>\n<p>Language preferences showed support for English and Russian, while timezone data indicated GMT+0300 (Eastern European Summer Time). <\/p>\n<p>A critical operational security failure occurred when the operator briefly connected without VPN protection, revealing an IP address associated with Ukrainian ISP TRK Cable TV. <\/p>\n<p>This breach demonstrates how MaaS supply chain vulnerabilities expose both infrastructure weaknesses and operator identities to security researchers.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/researchers-gain-access-to-stealc-malware-command-and-control-systems\/\">Researchers Gain Access to StealC Malware Command-and-Control Systems<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/researchers-gain-access-to-stealc-malware-command-and-control-systems\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Gain Access to StealC Malware Command-and-Control Systems Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor\u2019s identity through their own stolen session cookies. The breach highlights critical security failures in criminal operations built around credential theft. XSS Vulnerability Exposes StealC Operators StealC, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258],"tags":[130],"class_list":["post-9949","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9949"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9949"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9949\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}