Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Newegg’s $7,500 RTX 5090 card is a sad, depressing omen

    Casio’s new G-Shock Mudmaster GGB100X watches with quad sensors and Bluetooth officially arrive in the US

    As brands respond to AI search, walls crumble between paid and organic

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      Google releases Gemini 3.1 Flash Lite at 1/8th the cost of Pro

      March 4, 2026

      Huawei Watch GT Series

      March 4, 2026

      Weighing up the enterprise risks of neocloud providers

      March 3, 2026

      A stolen Gemini API key turned a $180 bill into $82,000 in two days

      March 3, 2026

      These ultra-budget laptops “include” 1.2TB storage, but most of it is OneDrive trial space

      March 1, 2026
    • Crypto

      Banks Respond to Kraken’s Federal Reserve Access as Trump Sides with Crypto

      March 4, 2026

      Hyperliquid and DEXs Break the Top 10 — Is the CEX Era Ending?

      March 4, 2026

      Consensus Hong Kong 2026: The Institutional Turn 

      March 4, 2026

      New Crypto Mutuum Finance (MUTM) Reports V1 Protocol Progress as Roadmap Enters Phase 3

      March 4, 2026

      Bitcoin Short Sellers Caught Off Guard in New White House Move

      March 4, 2026
    • Technology

      Newegg’s $7,500 RTX 5090 card is a sad, depressing omen

      March 6, 2026

      Casio’s new G-Shock Mudmaster GGB100X watches with quad sensors and Bluetooth officially arrive in the US

      March 6, 2026

      As brands respond to AI search, walls crumble between paid and organic

      March 6, 2026

      Why a Gen Alpha–focused skin-care brand is giving equity to teen creators

      March 6, 2026

      ‘Nobody’s asking the question’: WPP’s biggest restructure in years means nothing until CMOs say it does

      March 6, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»StealC hackers hacked as researchers hijack malware control panels
    Technology

    StealC hackers hacked as researchers hijack malware control panels

    TechAiVerseBy TechAiVerseJanuary 17, 2026No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    StealC hackers hacked as researchers hijack malware control panels
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    StealC hackers hacked as researchers hijack malware control panels

    A cross-site scripting (XSS) flaw in the web-based control panel used by operators of the StealC info-stealing malware allowed researchers to observe active sessions and gather intelligence on the attackers’ hardware.

    StealC emerged in early 2023 with aggressive promotion on dark web cybercrime channels. It grew in popularity due to its evasion and extensive data theft capabilities.

    In the following years, StealC’s developer added multiple enhancements. With the release of version 2.0 last April, the malware author introduced Telegram bot support for real-time alerts and a new builder that could generate StealC builds based on templates and custom data theft rules.

    Around that time, the source code for the malware’s administration panel was leaked, giving researchers an opportunity to analyze it.

    CyberArk researchers also discovered an XSS flaw that allowed them to collect browser and hardware fingerprints of StealC operators, observe active sessions, steal session cookies from the panel, and hijack panel sessions remotely.

    “By exploiting the vulnerability, we were able to identify characteristics of the threat actor’s computers, including general location indicators and computer hardware details,” the researchers say.

    “Additionally, we were able to retrieve active session cookies, which allowed us to gain control of sessions from our own machines.”

    The StealC builder panel
    Source: CyberArk

    CyberArk did not disclose specific details about the XSS vulnerability to prevent StealC operators from quickly pinpointing and fixing it.

    The report highlights one case of a StealC customer, referred to as ‘YouTubeTA’, who hijacked old, legitimate YouTube channels likely using compromised credentials, and planted infecting links.

    The cybercriminal ran malware campaigns throughout 2025, collecting over 5,000 victim logs, stealing approximately 390,000 passwords and 30 million cookies (most of them non-sensitive).

    Markers page on YouTubeTA’s panel
    Source: CyberArk

    Screenshots from the threat actor’s panel indicate that most infections occurred when victims searched for cracked versions of Adobe Photoshop and Adobe After Effects.

    By leveraging the XSS flaw, the researchers could determine that the attacker used an Apple M3-based system with English and Russian language settings, used the Eastern European time zone, and was accessing the internet via Ukraine.

    Their location was exposed when the threat actor forgot to connect the StealC panel through VPN. This revealed their real IP address, which was linked to Ukrainian ISP TRK Cable TV.

    CyberArk notes that malware-as-a-service (MaaS) platforms enable rapid scaling but also pose a significant risk of exposure to threat actors.

    BleepingComputer has contacted CyberArk to ask why they chose to disclose the StealC XSS flaw now. Researcher Ari Novick said that they hope to cause disruption to the operation, since there has been “a spike in recent months in the number of StealC operators, possibly in response to the drama around Lumma a couple of months ago.”

    “By posting the existence of the XSS we hope to cause at least some disruption in the use of the StealC malware, as operators re-evaluate using it. Since there are now relatively many operators, it seemed like a prime opportunity to potentially cause a fairly significant disruption in the MaaS market.”


    Secrets Security Cheat Sheet: From Sprawl to Control

    Whether you’re cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

    Get the cheat sheet and take the guesswork out of secrets management.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleBlack Basta boss makes it onto Interpol’s ‘Red Notice’ list
    Next Article OpenAI says its new ChatGPT ads won’t influence answers
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Newegg’s $7,500 RTX 5090 card is a sad, depressing omen

    March 6, 2026

    Casio’s new G-Shock Mudmaster GGB100X watches with quad sensors and Bluetooth officially arrive in the US

    March 6, 2026

    As brands respond to AI search, walls crumble between paid and organic

    March 6, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025705 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025291 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025165 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025125 Views
    Don't Miss
    Technology March 6, 2026

    Newegg’s $7,500 RTX 5090 card is a sad, depressing omen

    Newegg’s $7,500 RTX 5090 card is a sad, depressing omen Image: Asus Summary created by…

    Casio’s new G-Shock Mudmaster GGB100X watches with quad sensors and Bluetooth officially arrive in the US

    As brands respond to AI search, walls crumble between paid and organic

    Why a Gen Alpha–focused skin-care brand is giving equity to teen creators

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Newegg’s $7,500 RTX 5090 card is a sad, depressing omen

    March 6, 20262 Views

    Casio’s new G-Shock Mudmaster GGB100X watches with quad sensors and Bluetooth officially arrive in the US

    March 6, 20262 Views

    As brands respond to AI search, walls crumble between paid and organic

    March 6, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    Best TV Antenna of 2025

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.