Executive Summary
StealC and Amadey represent a sophisticated dual-threat ecosystem within the cybercrime-as-a-service market. StealC is a specialized C++ information stealer focused on harvesting browser secrets, cryptocurrency wallets, and session tokens, while Amadey serves as a modular loader and botnet used to distribute follow-on payloads including Lumma Stealer and LockBit 3.0 ransomware. Recent activity highlights their use by both financially motivated actors and state-sponsored groups like Secret Blizzard to profile targets and establish persistent footholds.
Technical analysis reveals that these threats employ advanced evasion and persistence mechanisms, such as APC injection to bypass Chromium App-Bound Encryption and scheduled tasks for longevity. The campaign infrastructure is global, utilizing compromised GitLab instances and SEO poisoning for delivery. A coordinated disruption in June 2026 by Microsoft and Europol targeted over 200 C2 domains, yet the modular nature of these tools allows for rapid infrastructure rotation and continued risk to enterprise environments through stolen session cookies and VPN credentials.
Key Details
Threat Name
StealC and Amadey
Affects
—
Adversary
Secret Blizzard Other Adversaries and Aliases: Fox Tempest; Vanilla Tempest; Storm-2697; Aquatic Panda
MITRE Techniques
Malware/Tools
StealC, Amadey, Lumma Stealer, RedLine, Raccoon, Vidar, The Gentlemen, Kazuar, SmokeLoader, LockBit 3.0, TinyNuke, Remcos RAT, SystemBC, VenomRAT, BRICKSTORM, Chinotto, Rustonotto
