FILEMembers
FILE

Stealc v2 Adds Chrome Encryption Bypass in Two-Stage Stealer Pivot

A credential-theft campaign previously tracked under a SmokeLoader lure has retooled around a sequenced SVCStealer loader and Stealc v2 payload, both beaconing to a single Spamhaus DROP-listed IP. The new Stealc v2 binary introduces a post-Chrome-127 app-bound encryption bypass, extending the operator's reach into modern browser credential stores that prior stealer versions could not access.

Jun 19, 2026, 09:13 (UTC+9)Last seenJun 19, 2026Severity87ByCTX TeamActorAPT28StrontiumIOC33MITRE42RegionsAU

Twelve new files and a single Spamhaus DROP-listed IP are the visible footprint of a credential-theft operation that has materially retooled since its earlier iteration. Where prior coverage documented a SmokeLoader-based lure with multiple C2 nodes, the campaign now deploys a sequenced SVCStealer loader and Stealc v2 payload — two unsigned 64-bit Windows executables that independently check in to the same raw IPv4 address, 62.60.226.159, hosted under AS214351 (Femo IT Solutions Limited,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence