Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
A cross-site scripting (XSS) vulnerability in the web-based control panel utilized by StealC information stealer operators has been revealed by cybersecurity experts, enabling them to obtain vital information about one of the threat actors utilizing the malware in their operations.
According to a paper released last week by CyberArk researcher Ari Novick, by exploiting it, we were able to collect system fingerprints, monitor active sessions, and—in a twist that will surprise no one—steal cookies from the very infrastructure designed to steal them.
StealC is an information stealer that first surfaced in January 2023 under a malware-as-a-service (MaaS) model. Potential users can use YouTube as a primary mechanism to spread the malicious program by disguising it as cracks for well-know...

