Analysis of StealC and Amadey Malware Lifecycle
Score: 9/10

Analysis of StealC and Amadey Malware Lifecycle

StealC and Amadey operate as a coordinated Malware-as-a-Service ecosystem to harvest credentials and provide initial access for ransomware and espionage operations.

Executive Summary

StealC and Amadey represent a sophisticated dual-threat ecosystem within the cybercrime-as-a-service market. StealC is a specialized C++ information stealer focused on harvesting browser secrets, cryptocurrency wallets, and session tokens, while Amadey serves as a modular loader and botnet used to distribute follow-on payloads including Lumma Stealer and LockBit 3.0 ransomware. Recent activity highlights their use by both financially motivated actors and state-sponsored groups like Secret Blizzard to profile targets and establish persistent footholds.

Technical analysis reveals that these threats employ advanced evasion and persistence mechanisms, such as APC injection to bypass Chromium App-Bound Encryption and scheduled tasks for longevity. The campaign infrastructure is global, utilizing compromised GitLab instances and SEO poisoning for delivery. A coordinated disruption in June 2026 by Microsoft and Europol targeted over 200 C2 domains, yet the modular nature of these tools allows for rapid infrastructure rotation and continued risk to enterprise environments through stolen session cookies and VPN credentials.

Key Details

Threat Name

StealC and Amadey

Affects

—

Adversary

Secret Blizzard Other Adversaries and Aliases: Fox Tempest; Vanilla Tempest; Storm-2697; Aquatic Panda

Malware/Tools

StealC, Amadey, Lumma Stealer, RedLine, Raccoon, Vidar, The Gentlemen, Kazuar, SmokeLoader, LockBit 3.0, TinyNuke, Remcos RAT, SystemBC, VenomRAT, BRICKSTORM, Chinotto, Rustonotto

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources