Researchers Gain Access to StealC Malware Command-and-Control Systems
The breach highlights critical security failures in criminal operations built around credential theft.
StealC, an information-stealing malware operating under a Malware-as-a-Service
By exploiting this flaw, CyberArk Labs collected system fingerprints, monitored active sessions, and captured authentication cookies from the infrastructure designed to steal them.
The irony proved significant: operators specializing in cookie theft failed to implement basic security features, such as the httpOnly flag, that would have prevented cookie hijacking via XSS attacks.
Through panel access, researchers tracked a single operator designated “YouTubeTA” (YouTube Threat Actor) who maintained over 5,000 infection logs containing 390,000 stolen passwords and 30 million cookies.
Screenshots captured by the malware showed victims searching for cracked versions of Adobe Photoshop and After Effects on YouTube, suggesting that YouTubeTA compromised legitimate YouTube channels with established subscriber bases to distribute StealC.
The operator’s panel configuration included specific markers for studio.youtube.com credentials, indicating a strategy to hijack content creator accounts and expand malware distribution networks.
Panel fingerprinting identified YouTubeTA as a single operator using an Apple M3 processor, with consistent hardware signatures across all sessions, as reported by CyberArk Labs .
Language preferences showed support for English and Russian, while timezone data indicated GMT+0300 (Eastern European Summer Time).
A critical operational security failure occurred when the operator briefly connected without VPN protection, revealing an IP address associated with Ukrainian ISP TRK Cable TV.
This breach demonstrates how MaaS supply chain vulnerabilities expose both infrastructure weaknesses and operator identities to security researchers.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Researchers Gain Access to StealC Malware Command-and-Control Systems appeared first on Cyber Security News.
Today, Pokémon Winds and Pokémon Waves were announced during a Pokémon Presents, showing off a…
Samsung's newest smartphones - the Galaxy S26, S26+, and S26 Ultra - were recently announced…
LEGO and Pokémon were my childhood (well, those and TMNT, but that’s for another time).…
From @Sam Nichols: Sunny, warm, and windy this weekend
From @Sam Nichols: Sunny, warm, and windy this weekend
From @Sam Nichols: Sunny, warm, and windy this weekend
This website uses cookies.