
Stealc v2 Adds Chrome Encryption Bypass in Two-Stage Stealer Pivot
A credential-theft campaign previously tracked under a SmokeLoader lure has retooled around a sequenced SVCStealer loader and Stealc v2 payload, both beaconing to a single Spamhaus DROP-listed IP. The new Stealc v2 binary introduces a post-Chrome-127 app-bound encryption bypass, extending the operator's reach into modern browser credential stores that prior stealer versions could not access.
Twelve new files and a single Spamhaus DROP-listed IP are the visible footprint of a credential-theft operation that has materially retooled since its earlier iteration. Where prior coverage documented a SmokeLoader-based lure with multiple C2 nodes, the campaign now deploys a sequenced SVCStealer loader and Stealc v2 payload — two unsigned 64-bit Windows executables that independently check in to the same raw IPv4 address, 62.60.226.159, hosted under AS214351 (Femo IT Solutions Limited,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read