Security Bug In StealC Malware Panel Let Researchers Spy On Threat Actor Operations
CyberArk, Sunday, April 19th, 2026
Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control panel used by operators of the StealC information stealer, allowing them to gather crucial insights on one of the threat actors using the malware in their operations.
"By exploiting it, we were able to collect system fingerprints, monitor active sessions, and - in a twist that will surprise no one - steal cookies from the very infrastructure designed to steal them," CyberArk researcher Ari Novick said in a report published last week.
StealC is an information stealer that first emerged in January 2023 under a malware-as-a-service (MaaS) model, allowing potential customers to leverage YouTube as a primary mechanism - a phenomenon called the YouTube Ghost Network - to distribute the malicious program by disguising it as cracks for popular software.